Vulnerabilities (CVE)

Filtered by vendor Bea Subscribe
Filtered by product Aqualogic Service Bus
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-0433 1 Bea 1 Aqualogic Service Bus 2023-12-10 6.5 MEDIUM N/A
Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.
CVE-2007-0432 1 Bea 1 Aqualogic Service Bus 2023-12-10 7.5 HIGH N/A
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.