The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-05-19T10:00:00
Updated: 2024-08-07T17:51:04.757Z
Reserved: 2006-05-19T00:00:00
Link: CVE-2006-2469
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-05-19T10:02:00.000
Modified: 2024-11-21T00:11:22.857
Link: CVE-2006-2469
Redhat
No data.