RSS   Vulnerabilities for 'Aqualogic interaction'   RSS

2007-12-01
 
CVE-2007-6198

CWE-Other
 

 
portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.

 
 
CVE-2007-6197

CWE-200
 

 
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.

 

 >>> Vendor: BEA 11 Products
Weblogic server
Tuxedo
Weblogic integration
Liquid data
Weblogic portal
Jrockit
Aqualogic service bus
Aqualogic enterprise security
Weblogic workshop
Aqualogic interaction
Weblogic mobility server


Copyright 2024, cxsecurity.com

 

Back to Top