CVE-2007-5576
CVSS 6.8 - MEDIUM
Description
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
Affected Products
50 of 56| Vendor | Product | Version |
|---|---|---|
| bea | tuxedo |
8.0
|
| bea | tuxedo |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
8.1
|
| bea | weblogic_integration |
9.2
|
| bea | weblogic_server |
5.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
6.1
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0
|
| bea | weblogic_server |
7.0.0.1
|
| bea | weblogic_server |
7.0.0.1
|
| bea | weblogic_server |
7.0.0.1
|
| bea | weblogic_server |
7.0.0.1
|
| bea | weblogic_server |
7.0.0.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
8.1
|
| bea | weblogic_server |
9.0
|
| bea | weblogic_server |
9.1
|
| bea | weblogic_server |
9.1
|
| bea | weblogic_server |
9.2
|
| bea | weblogic_server |
9.2
|
Showing first 50 of 56 affected products.
References
Weakness Types
CWE-200
CVE Information
- CVE ID:
CVE-2007-5576- Published:
- 2007-10-18
- Modified:
- 2026-04-23
- CVSS Score:
- 6.8
- Severity:
- MEDIUM
- Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C
Affected Vendors
oracle
bea
Quick Actions
CVSS Severity Scale
0.0 - 3.9
LOW
4.0 - 6.9
MEDIUM
7.0 - 8.9
HIGH
9.0 - 10.0
CRITICAL