Title: BEA WebLogic -D Switch Server Log Cleartext Credential Disclosure
Info
Disclosure
Oct 10, 2005
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
BEA WebLogic contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when system properties are supplied on the Java command-line by using the -D switch when booting the server, which may allow a remote attacker with read access to the server log to disclose sensitive information resulting in a loss of confidentiality.
Classification
Location:
Remote/Network Access Required
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 8.1 Service Pack 5 or 7.0 Service Pack 6 higher, as it has been reported to fix this vulnerability. In addition, BEA Systems has released a patch for version 6.1 Service Pack 7.