VulnerabilityModified
CVE-2007-6197
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
MEDIUM 5.0EPSS 1.58%
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- bea/aqualogic interaction
- Source
- cve@mitre.org
References
- http://procheckup.com/Vulnerability_PR06-08.phpExploit
- http://procheckup.com/Vulnerability_PR06-09.phpExploit
- http://secunia.com/advisories/27840Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/484467/100/0/threaded
- http://www.securitytracker.com/id?1019005
- http://www.vupen.com/english/advisories/2007/4040
- http://procheckup.com/Vulnerability_PR06-08.phpExploit
- http://procheckup.com/Vulnerability_PR06-09.phpExploit
- http://secunia.com/advisories/27840Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/484467/100/0/threaded
- http://www.securitytracker.com/id?1019005
- http://www.vupen.com/english/advisories/2007/4040
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.