Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qm3-5x8f-7qqj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.

The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.

EPSS

Процентиль: 71%
0.00692
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.

EPSS

Процентиль: 71%
0.00692
Низкий