First published: Mon Dec 31 2001(Updated: )
The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA Tuxedo | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1477 is classified as a high severity vulnerability due to unauthorized access to services in remote domains.
To fix CVE-2001-1477, ensure proper authorization checks are implemented for imported services and qspaces on remote domains.
CVE-2001-1477 affects BEA Tuxedo version 7.1.
CVE-2001-1477 allows unauthorized users to access sensitive services across remote domains, leading to potential data breaches.
Mitigating CVE-2001-1477 without updating software may involve implementing stricter network controls and monitoring to limit unauthorized access.