PT-2007-1904 · Bea+1 · Bea Aqualogic Enterprise Security+1
Published
2007-01-23
·
Updated
2008-11-13
·
CVE-2007-0433
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA AquaLogic Enterprise Security versions 2.0 through 2.0 SP2
BEA AquaLogic Enterprise Security versions 2.1 through 2.1 SP1
BEA AquaLogic Enterprise Security version 2.2
Description
The issue allows remote authenticated users to access the server even after the account has been disabled, when using Active Directory LDAP for authentication.
Recommendations
For versions 2.0 through 2.0 SP2, consider disabling Active Directory LDAP authentication until a fix is available.
For versions 2.1 through 2.1 SP1, consider disabling Active Directory LDAP authentication until a fix is available.
For version 2.2, consider disabling Active Directory LDAP authentication until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Active Directory Ldap
Bea Aqualogic Enterprise Security