VulnerabilityModified
CVE-2007-0434
BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.
MEDIUM 4.6EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- bea/aqualogic enterprise security
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/220Vendor Advisory
- http://osvdb.org/32860
- http://secunia.com/advisories/23786Vendor Advisory
- http://www.securityfocus.com/bid/22082
- http://dev2dev.bea.com/pub/advisory/220Vendor Advisory
- http://osvdb.org/32860
- http://secunia.com/advisories/23786Vendor Advisory
- http://www.securityfocus.com/bid/22082
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.