BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-08-16T04:00:00
Updated: 2024-08-08T02:19:46.030Z
Reserved: 2005-08-16T00:00:00
Link: CVE-2003-1222
Vulnrichment
No data.
NVD
Status : Modified
Published: 2003-12-31T05:00:00.000
Modified: 2024-11-20T23:46:38.607
Link: CVE-2003-1222
Redhat
No data.