Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jcq-7m4x-57r2

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

EPSS

Процентиль: 37%
0.00162
Низкий

Связанные уязвимости

nvd
почти 22 года назад

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

EPSS

Процентиль: 37%
0.00162
Низкий