CVE-2007-0433
Summary
| CVE | CVE-2007-0433 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-23 02:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Aqualogic Service Bus | 2.0 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp2 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BEA AquaLogic Weakness and Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Upgrade and patch are available to disable users in Active Directory LDAP server | af854a3a-2127-422b-91ae-364da2661108 | dev2dev.bea.com | Vendor Advisory |
| SecurityTracker.com Archives - BEA AquaLogic Enterprise Security Lets Disabled User Accounts Access the System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Vendor Advisory |
| BEA Multiple Products Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/32861 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.