HIGH · 7.5

CVE-2007-0432

BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route reques...

Vulnerability Description

BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BeaAqualogic Service Bus2.0

References

FAQ

What is CVE-2007-0432?

CVE-2007-0432 is a vulnerability with a CVSS score of 7.5 (HIGH). BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route reques...

How severe is CVE-2007-0432?

CVE-2007-0432 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0432?

Check the references section above for vendor advisories and patch information. Affected products include: Bea Aqualogic Service Bus.