Bea Aqualogic Interaction vulnerabilities
2 known vulnerabilities affecting bea/aqualogic_interaction.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2007-6198P4MEDIUMCVSS 5.0PoCv5.0.2v5.0.3+2 more2007-12-01
CVE-2007-6198 [MEDIUM] CVE-2007-6198: portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.2
portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.
nvd
CVE-2007-6197P4MEDIUMCVSS 5.0v5.0.2v5.0.3+2 more2007-12-01
CVE-2007-6197 [MEDIUM] CWE-200 CVE-2007-6197: The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
nvd