CVE-2007-6197: Infoleak
Published Dec 1, 2007
·Updated
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
Affected Software
4 affected components
Bea AquaLogic Interaction=5.0.2
Bea AquaLogic Interaction=5.0.3
Bea AquaLogic Interaction=5.0.4
Bea AquaLogic Interaction=6.0.1.218452
Remediation
Patch Available
Event History
Dec 1, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6197?
CVE-2007-6197 has a medium severity level due to its ability to expose sensitive information.
2
How do I fix CVE-2007-6197?
To fix CVE-2007-6197, update your BEA AquaLogic Interaction software to a version that addresses this vulnerability.
3
What products are affected by CVE-2007-6197?
CVE-2007-6197 affects BEA AquaLogic Interaction versions 5.0.2 through 5.0.4 and 6.0.1.218452.
4
What type of vulnerability is CVE-2007-6197?
CVE-2007-6197 is an information disclosure vulnerability that allows attackers to view internal hostnames and version numbers.
5
What can attackers achieve with CVE-2007-6197?
Attackers exploiting CVE-2007-6197 can obtain sensitive information that may aid in further attacks.