First published: Tue Jan 23 2007(Updated: )
BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA AquaLogic Enterprise Security | =2.0 | |
BEA AquaLogic Enterprise Security | =2.0-sp1 | |
BEA AquaLogic Enterprise Security | =2.0-sp2 | |
BEA AquaLogic Enterprise Security | =2.1 | |
BEA AquaLogic Enterprise Security | =2.1-sp1 | |
BEA AquaLogic Enterprise Security | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-0434 is classified as a medium vulnerability due to improper audit event handling under high system load.
To fix CVE-2007-0434, ensure you apply the latest patches or updates provided by BEA for AquaLogic Enterprise Security.
CVE-2007-0434 affects BEA AquaLogic Enterprise Security versions 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2.
The potential risks of CVE-2007-0434 include minimized detection capabilities for unauthorized access or attacks due to insufficient audit severity settings.
CVE-2007-0434 is not directly related to denial of service attacks, but it could help attackers evade detection during such attacks.