4
CVSSv2

CVE-2007-2700

Published: 16/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The WLST script generated by the configToScript command in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not encrypt certain attributes in configuration files when creating a new domain, which allows remote authenticated users to obtain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 9.1

bea weblogic server 9.0