CVE-2007-6198: Medium severity Bea AquaLogic Interaction vulnerability
portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the intxfulltext parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6198?
CVE-2007-6198 is classified as a medium severity vulnerability due to its potential for username enumeration.
How do I fix CVE-2007-6198?
To fix CVE-2007-6198, users should apply security patches provided by BEA AquaLogic Interaction for affected versions.
What systems are affected by CVE-2007-6198?
CVE-2007-6198 affects BEA AquaLogic Interaction versions 5.0.2 through 5.0.4 and 6.0.1.218452.
What type of vulnerability is CVE-2007-6198?
CVE-2007-6198 is a security vulnerability that allows remote attackers to enumerate valid usernames.
What is the attack vector for CVE-2007-6198?
The attack vector for CVE-2007-6198 is through the in_tx_fulltext parameter during advanced searches.