Vulnerability Details CVE-2007-0432
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 56.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2007-0432
-
cpe:2.3:a:bea:aqualogic_service_bus:2.0
-
cpe:2.3:a:bea:aqualogic_service_bus:2.1
-
cpe:2.3:a:bea:aqualogic_service_bus:2.5