CVE

Id
23789  
CVE No.
CVE-2007-0432  
Status
Candidate  
Description
BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.  
Phase
Assigned (20070122)  
Votes
None (candidate not yet proposed)  
Comments