← Back

Aqualogic Service Bus

aqualogic_service_bus

Vendor: Bea • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bea
1Aqualogic Service Bus
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the serve...Show more
Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.Show less
1Bea
1Aqualogic Service Bus
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end servi...Show more
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.Show less