VulnerabilityModified
CVE-2007-0433
Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been…
MEDIUM 6.5EPSS 1.27%
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- bea/aqualogic service bus
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/221Vendor Advisory
- http://osvdb.org/32861
- http://secunia.com/advisories/23786Vendor Advisory
- http://securitytracker.com/id?1017524Vendor Advisory
- http://www.securityfocus.com/bid/22082
- http://dev2dev.bea.com/pub/advisory/221Vendor Advisory
- http://osvdb.org/32861
- http://secunia.com/advisories/23786Vendor Advisory
- http://securitytracker.com/id?1017524Vendor Advisory
- http://www.securityfocus.com/bid/22082
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.