CVE Database · CVE-2006-0423
CVSS v3.1
N/A
EPSS
4.37%
Published
Jan 25, 2006
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.
Affected Products (4)
References (18)