BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-04-01T02:00:00Z

Updated: 2024-09-16T17:47:51.455Z

Reserved: 2006-03-31T00:00:00Z

Link: CVE-2005-4761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-12-31T05:00:00.000

Modified: 2008-09-05T20:57:45.047

Link: CVE-2005-4761

cve-icon Redhat

No data.