CVE-2007-0433
Summary
| CVE | CVE-2007-0433 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-23 02:28:00 UTC |
| Updated | 2008-11-13 06:31:00 UTC |
| Description | Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Aqualogic Service Bus | 2.0 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp2 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.2 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.0 | sp2 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | All | All | All |
| Application | Bea | Aqualogic Service Bus | 2.1 | sp1 | All | All |
| Application | Bea | Aqualogic Service Bus | 2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - BEA AquaLogic Enterprise Security Lets Disabled User Accounts Access the System | SECTRACK | securitytracker.com | Vendor Advisory |
| BEA Multiple Products Multiple Vulnerabilities | BID | www.securityfocus.com | |
| Upgrade and patch are available to disable users in Active Directory LDAP server | BEA | dev2dev.bea.com | Vendor Advisory |
| BEA AquaLogic Weakness and Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| 32861 | OSVDB | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.