CVE-2007-5576
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
BEA Tuxedo 8.0 anterior al RP392 y el 8.1 anterior al RP293 y el WebLogic Enterprise 5.1 anterior al RP174, muestra la contraseña en texto claro, lo que permite a atacantes físicamente próximos obtener información sensible a través de los comandos (1) cnsbind, (2) cnsunbind o (3) cnsls.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-10-18 CVE Reserved
- 2007-10-18 CVE Published
- 2023-08-14 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/45478 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1813 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34290 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://dev2dev.bea.com/pub/advisory/226 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bea Search vendor "Bea" | Tuxedo Search vendor "Bea" for product "Tuxedo" | 8.0 Search vendor "Bea" for product "Tuxedo" and version "8.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Tuxedo Search vendor "Bea" for product "Tuxedo" | 8.1 Search vendor "Bea" for product "Tuxedo" and version "8.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 8.1 Search vendor "Bea" for product "Weblogic Integration" and version "8.1" | sp6 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Integration Search vendor "Bea" for product "Weblogic Integration" | 9.2 Search vendor "Bea" for product "Weblogic Integration" and version "9.2" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 5.1 Search vendor "Bea" for product "Weblogic Server" and version "5.1" | enterprise |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp5, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp6, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp7, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp6 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp6, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp7 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp7, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp5, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.0 Search vendor "Bea" for product "Weblogic Server" and version "9.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.1 Search vendor "Bea" for product "Weblogic Server" and version "9.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.1 Search vendor "Bea" for product "Weblogic Server" and version "9.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.2 Search vendor "Bea" for product "Weblogic Server" and version "9.2" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.2 Search vendor "Bea" for product "Weblogic Server" and version "9.2" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Workshop Search vendor "Bea" for product "Weblogic Workshop" | 8.1 Search vendor "Bea" for product "Weblogic Workshop" and version "8.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Workshop Search vendor "Bea" for product "Weblogic Workshop" | 8.1 Search vendor "Bea" for product "Weblogic Workshop" and version "8.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Workshop Search vendor "Bea" for product "Weblogic Workshop" | 8.1 Search vendor "Bea" for product "Weblogic Workshop" and version "8.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Workshop Search vendor "Bea" for product "Weblogic Workshop" | 8.1 Search vendor "Bea" for product "Weblogic Workshop" and version "8.1" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Workshop Search vendor "Bea" for product "Weblogic Workshop" | 8.1 Search vendor "Bea" for product "Weblogic Workshop" and version "8.1" | sp6 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Portal Search vendor "Oracle" for product "Weblogic Portal" | 9.2 Search vendor "Oracle" for product "Weblogic Portal" and version "9.2" | - |
Affected
|