VYPR
Unrated severityNVD Advisory· Published Apr 13, 2004· Updated Jun 16, 2026

CVE-2004-1758

CVE-2004-1758

Description

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

39
  • Bea/WebLogic Server38 versions
    cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*+ 37 more
    • cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:win32:*:*:*:*:*
    • (no CPE)range: <=8.1 SP2, <=7.0 SP4, <=6.1 SP6
  • Range: <=8.1 SP2, <=7.0 SP4, <=6.1 SP6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.