Title: BEA WebLogic Keystore Clear Text Password Storage Vulnerability
Severity: MODERATE
Description:
BEA Systems WebLogic Server is an enterprise level Java web application server.
A problem has been reported that may allow the recovery of sensitive information.
It has been reported that BEA WebLogic servers are vulnerable to potential password recovery when keystores are used. In the event that an attacker could gain access to one of these keystores, it would be possible for the attacker to discover authentication information that could result in a potential compromise of communication integrity.
The problem is in the securing of information in keystores. Keystores are typically used to store the server private key, and certificate authority information. However, information contained in the keystore is stored in plain text, making it possible for any user with access to the keystore to easily recover the information.
Affected Products:
- BEA Systems WebLogic Express 7.0.0
- BEA Systems WebLogic Express 7.0.0 .0.1
- BEA Systems WebLogic Express 7.0.0 .0.1 SP 1
- BEA Systems WebLogic Express 7.0.0 SP 1
- BEA Systems WebLogic Express for Win32 7.0.0
- BEA Systems WebLogic Express for Win32 7.0.0 .0.1
- BEA Systems WebLogic Express for Win32 7.0.0 .0.1 SP 1
- BEA Systems WebLogic Express for Win32 7.0.0 SP 1
- BEA Systems WebLogic Server for Win32 7.0.0
- BEA Systems WebLogic Server for Win32 7.0.0 .0.1
- BEA Systems WebLogic Server for Win32 7.0.0 .0.1 SP 1
- BEA Systems WebLogic Server for Win32 7.0.0 SP 1
- BEA Systems Weblogic Server 7.0.0
- BEA Systems Weblogic Server 7.0.0 .0.1
- BEA Systems Weblogic Server 7.0.0 .0.1 SP 1
- BEA Systems Weblogic Server 7.0.0 SP 1
References:
- BEA Systems: SECURITY ADVISORY (BEA03-25.00)
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.