CVE-2008-0904: Infoleak
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0904?
CVE-2008-0904 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2008-0904?
To mitigate CVE-2008-0904, it is recommended to upgrade to the latest versions of BEA Plumtree Collaboration and AquaLogic Interaction that contain patches.
Which versions are affected by CVE-2008-0904?
CVE-2008-0904 affects BEA Plumtree Collaboration versions 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1.
Can CVE-2008-0904 be exploited remotely?
Yes, CVE-2008-0904 can be exploited remotely by sending crafted URLs to the vulnerable application.
What type of files can be accessed through CVE-2008-0904?
CVE-2008-0904 allows attackers to read arbitrary files on the server, which can lead to sensitive information disclosure.