CVE-2005-4761 Information

Description

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier 7.0 SP5 and earlier and 6.1 SP7 and earlier log the Java command line at server startup which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.

Reference

http://dev2dev.bea.com/pub/advisory/152 http://secunia.com/advisories/17138 http://www.securityfocus.com/bid/15052

Share on: