The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
2007-12-01T06:46:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bea | aqualogic_interaction | 5.0.2 | Yes |
Application | bea | aqualogic_interaction | 5.0.3 | Yes |
Application | bea | aqualogic_interaction | 5.0.4 | Yes |
Application | bea | aqualogic_interaction | 6.0.1.218452 | Yes |