First published: Tue Jan 23 2007(Updated: )
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA AquaLogic Service Bus | =2.0 | |
BEA AquaLogic Service Bus | =2.1 | |
BEA AquaLogic Service Bus | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0432 is considered a high severity vulnerability due to its potential to allow unauthorized access to back-end services.
To fix CVE-2007-0432, upgrade to a patched version of BEA AquaLogic Service Bus that properly handles malformed request messages.
CVE-2007-0432 affects BEA AquaLogic Service Bus versions 2.0, 2.1, and 2.5.
CVE-2007-0432 can enable remote attackers to bypass authorization policies and conduct unauthorized activities.
Yes, CVE-2007-0432 is a web application security vulnerability that impacts how request messages are processed.