BEA Plumtree Portal Search Function Discloses Usernames to Remote Users
|
|
SecurityTracker Alert ID: 1019004
|
|
SecurityTracker URL: http://securitytracker.com/id?1019004
|
|
CVE Reference: CVE-2007-6198
(Links to External Site)
|
Updated: Dec 3 2007
|
Original Entry Date: Nov 28 2007
|
Impact: Disclosure of system information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: BEA Security Advisory
|
Version(s): Plumtree Foundation 6.0 through SP1, AquaLogic Interaction 6.1 through SP1
|
Description: A vulnerability was reported in BEA Plumtree Portal. A remote user can determine valid usernames.
A remote user can execute an advance search request containing wildcards to cause the system to return usernames.
BEA Plumtree
Foundation and BEA AquaLogic Interaction 6.1 are affected.
The vendor was notified on May 18, 2007.
Adrian Pastor and Jan
Fry from ProCheckUp Ltd. reported this vulnerability.
The original advisory is available at:
http://procheckup.com/Vulnerability_PR06-11.php
|
Impact: A remote user can determine valid usernames on the target system.
|
Solution: The vendor has described a configuration process to address this vulnerability in their advisory.
The BEA advisory is available at:
http://dev2dev.bea.com/pub/advisory/254
|
Vendor URL: dev2dev.bea.com/pub/advisory/254 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 27 Nov 2007 23:25:25 -0500
Subject: PR06-11: BEA Plumtree portal search facility leaks usernames to unauthenticated users
|
http://procheckup.com/Vulnerability_PR06-11.php
|
|