Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.
2007-01-23T02:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bea | aqualogic_service_bus | 2.0 | Yes |
Application | bea | aqualogic_service_bus | 2.0 | Yes |
Application | bea | aqualogic_service_bus | 2.0 | Yes |
Application | bea | aqualogic_service_bus | 2.1 | Yes |
Application | bea | aqualogic_service_bus | 2.1 | Yes |
Application | bea | aqualogic_service_bus | 2.2 | Yes |