HomeBeaCVE-2007-2700

CVE-2007-2700

UNKNOWN
4.0CVSS
Published: 2007-05-16
Updated: 2025-04-09
AI Analysis

Description

The WLST script generated by the configToScript command in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not encrypt certain attributes in configuration files when creating a new domain, which allows remote authenticated users to obtain sensitive information.

CVSS Metrics

Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Access Vector
network
Access Cmplx
low
Auth
single
Confidentiality
partial
Integrity
none
Availability
none
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
BEA
Published
5/16/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

bea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-2700 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com