First published: Tue Jan 23 2007(Updated: )
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA AquaLogic Service Bus | =2.0 | |
BEA AquaLogic Service Bus | =2.1 | |
BEA AquaLogic Service Bus | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.