BEA Plumtree Portal Discloses Internal Hostname and Product Version Number to Remote Users
|
|
SecurityTracker Alert ID: 1019005
|
|
SecurityTracker URL: http://securitytracker.com/id?1019005
|
|
CVE Reference: CVE-2007-6197
(Links to External Site)
|
Updated: Dec 3 2007
|
Original Entry Date: Nov 28 2007
|
Impact: Disclosure of system information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: BEA Security Advisory
|
Version(s): Plumtree Foundation 6.0 through SP1, AquaLogic Interaction 6.1 through SP1
|
Description: A vulnerability was reported in BEA Plumtree Portal. A remote user can determine the internal hostname and the version number.
The internal hostname of the server hosting the BEA Plumtree portal and the version and build date of the portal are included within
HTML comments in every page served.
BEA Plumtree Foundation and BEA AquaLogic Interaction are affected.
The vendor was notified
on May 18, 2007.
Adrian Pastor and Jan Fry from ProCheckUp Ltd. reported this vulnerability.
The original advisories are available
at:
http://procheckup.com/Vulnerability_PR06-08.php
http://procheckup.com/Vulnerability_PR06-09.php
|
Impact: A remote user can determine the internal hostname of the server and the product version number of the portal software.
|
Solution: The vendor has described a configuration process to address these vulnerabilities in their advisories.
The BEA advisories are available at:
http://dev2dev.bea.com/pub/advisory/251
http://dev2dev.bea.com/pub/advisory/252
|
Vendor URL: dev2dev.bea.com/pub/advisory/251 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 27 Nov 2007 23:28:27 -0500
Subject: PR06-08: BEA Plumtree portal internal hostname disclosure vulnerability
|
http://procheckup.com/Vulnerability_PR06-08.php
PR06-09: BEA Plumtree portal full version disclosure vulnerability
http://procheckup.com/Vulnerability_PR06-09.php
|
|