BEA WebLogic密钥库清除文本密码存储漏洞

漏洞信息详情

BEA WebLogic密钥库清除文本密码存储漏洞

漏洞简介

BEA WebLogic Express以及WebLogic Server 7.0版本和7.0.0.1版本,在密钥库被用来存储私钥或信托证书权限时在明文中储存密码,本地用户可以获得权限。

漏洞公告

BEA has made fixes available. These fixes require upgrading to Service Pack 1 of the respective release chain prior to patch application. See the vendor web page reference for more details.
BEA Systems WebLogic Server for Win32 7.0 SP 1

BEA Systems WebLogic Server for Win32 7.0 .0.1

BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1

BEA Systems WebLogic Server for Win32 7.0

BEA Systems WebLogic Express 7.0 .0.1

BEA Systems WebLogic Express for Win32 7.0 SP 1

BEA Systems Weblogic Server 7.0 .0.1

BEA Systems WebLogic Express for Win32 7.0

BEA Systems WebLogic Express for Win32 7.0 .0.1

BEA Systems WebLogic Express 7.0 .0.1 SP 1

BEA Systems Weblogic Server 7.0 .0.1 SP 1

BEA Systems WebLogic Express 7.0

BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1

BEA Systems Weblogic Server 7.0 SP 1

BEA Systems Weblogic Server 7.0

BEA Systems WebLogic Express 7.0 SP 1

参考网址

来源: BEA
名称: BEA03-25.00
链接:http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp

来源: XF
名称: weblogic-keystore-plaintext-passwords(11220)
链接:http://xforce.iss.net/xforce/xfdb/11220

来源: BID
名称: 6719
链接:http://www.securityfocus.com/bid/6719

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享