CVE-2007-5576

Published Oct 18, 2007

Last updated 6 years ago

Overview

Description
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
10
Exploitability score
3.1
Vector string
AV:L/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-200

Social media

Hype score
Not currently trending

Evaluator

Comment
-
Impact
-
Solution
-

Configurations