CVE-2003-1437
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2003
Last modified:
03/04/2025
Description
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:hp-ux:11.11i:v1:*:*:*:*:*:* | ||
cpe:2.3:o:ibm:aix:4.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_nt:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:redhat:linux:6.2:*:i386:*:*:*:*:* | ||
cpe:2.3:o:redhat:linux:7.1:*:i386:*:*:*:*:* | ||
cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:* | ||
cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:* | ||
cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:express:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:express:*:*:*:*:* | ||
cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp
- http://www.securityfocus.com/bid/6719
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11220
- http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp
- http://www.securityfocus.com/bid/6719
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11220