CVE-2001-1477: Medium severity Bea Tuxedo vulnerability
The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1477?
CVE-2001-1477 is classified as a high severity vulnerability due to unauthorized access to services in remote domains.
How do I fix CVE-2001-1477?
To fix CVE-2001-1477, ensure proper authorization checks are implemented for imported services and qspaces on remote domains.
What software versions are affected by CVE-2001-1477?
CVE-2001-1477 affects BEA Tuxedo version 7.1.
What impact does CVE-2001-1477 have on security?
CVE-2001-1477 allows unauthorized users to access sensitive services across remote domains, leading to potential data breaches.
Can CVE-2001-1477 be mitigated without updating software?
Mitigating CVE-2001-1477 without updating software may involve implementing stricter network controls and monitoring to limit unauthorized access.