CVE-2007-5576

CVSS 6.8 - MEDIUM
Description

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.

Affected Products
50 of 56
Vendor Product Version
bea tuxedo 8.0
bea tuxedo 8.1
bea weblogic_integration 8.1
bea weblogic_integration 8.1
bea weblogic_integration 8.1
bea weblogic_integration 8.1
bea weblogic_integration 8.1
bea weblogic_integration 8.1
bea weblogic_integration 9.2
bea weblogic_server 5.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 6.1
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0
bea weblogic_server 7.0.0.1
bea weblogic_server 7.0.0.1
bea weblogic_server 7.0.0.1
bea weblogic_server 7.0.0.1
bea weblogic_server 7.0.0.1
bea weblogic_server 8.1
bea weblogic_server 8.1
bea weblogic_server 8.1
bea weblogic_server 8.1
bea weblogic_server 8.1
bea weblogic_server 8.1
bea weblogic_server 9.0
bea weblogic_server 9.1
bea weblogic_server 9.1
bea weblogic_server 9.2
bea weblogic_server 9.2
Showing first 50 of 56 affected products.
Weakness Types
CWE-200
CVE Information
CVE ID:
CVE-2007-5576
Published:
2007-10-18
Modified:
2026-04-23
CVSS Score:
6.8
Severity:
MEDIUM
Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C
Affected Vendors
oracle bea
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL