CVE-2007-6197
Summary
| CVE | CVE-2007-6197 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-01 06:46:00 UTC |
| Updated | 2018-10-15 21:50:00 UTC |
| Description | The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Aqualogic Interaction | 5.0.2 | All | All | All |
| Application | Bea | Aqualogic Interaction | 5.0.3 | All | All | All |
| Application | Bea | Aqualogic Interaction | 5.0.4 | All | All | All |
| Application | Bea | Aqualogic Interaction | 6.0.1.218452 | All | All | All |
| Application | Bea | Aqualogic Interaction | 5.0.2 | All | All | All |
| Application | Bea | Aqualogic Interaction | 5.0.3 | All | All | All |
| Application | Bea | Aqualogic Interaction | 5.0.4 | All | All | All |
| Application | Bea | Aqualogic Interaction | 6.0.1.218452 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| BEA AquaLogic Interaction Plumtree Portal Information Disclosure - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| ProCheckUp - Security Vulnerabilities 2007 | MISC | procheckup.com | Exploit |
| BEA Plumtree Portal Discloses Internal Hostname and Product Version Number to Remote Users - SecurityTracker | SECTRACK | www.securitytracker.com | |
| ProCheckUp - Security Vulnerabilities 2007 | MISC | procheckup.com | Exploit |
| Webmail - OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.