December 14, 2001

Websphere reveals system root password

Author: JT Smith

NetSecurity: "On default installation WebSphere installs itself to run with root-identity, and stores
root password as a clear text to a file $WASROOT/properties/sas.server.props. The file
has permissions 600, and therefore other users on system cannot access it."


  • Linux
