Loading
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
Cite this page
CVE-2007-5576. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2007-5576
Use CWE-200, Bea vendor hub and Tuxedo product page to widen CVE-2007-5576 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2003-0622, CVE-2003-0621 and CVE-2001-1477 for nearby disclosures in the same product family.