CVE-2007-0432: High severity Bea AquaLogic Service Bus vulnerability
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0432?
CVE-2007-0432 is considered a high severity vulnerability due to its potential to allow unauthorized access to back-end services.
How do I fix CVE-2007-0432?
To fix CVE-2007-0432, upgrade to a patched version of BEA AquaLogic Service Bus that properly handles malformed request messages.
What versions of BEA AquaLogic Service Bus are affected by CVE-2007-0432?
CVE-2007-0432 affects BEA AquaLogic Service Bus versions 2.0, 2.1, and 2.5.
What type of attacks can CVE-2007-0432 enable?
CVE-2007-0432 can enable remote attackers to bypass authorization policies and conduct unauthorized activities.
Is CVE-2007-0432 related to web application security?
Yes, CVE-2007-0432 is a web application security vulnerability that impacts how request messages are processed.