First published: Fri Feb 22 2008(Updated: )
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bea Systems Plumtree Collaboration | =4.1_sp2 | |
Bea Systems Aqualogic Interaction | =4.2 | |
Bea Systems Plumtree Collaboration | =4.1_sp1 | |
Bea Systems Plumtree Collaboration | =4.1 | |
Bea Systems Aqualogic Interaction | =4.2_mp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0904 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To mitigate CVE-2008-0904, it is recommended to upgrade to the latest versions of BEA Plumtree Collaboration and AquaLogic Interaction that contain patches.
CVE-2008-0904 affects BEA Plumtree Collaboration versions 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1.
Yes, CVE-2008-0904 can be exploited remotely by sending crafted URLs to the vulnerable application.
CVE-2008-0904 allows attackers to read arbitrary files on the server, which can lead to sensitive information disclosure.