Vulnerabilities > BEA > Aqualogic Interaction > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-12-01 CVE-2007-6198 Information Disclosure vulnerability in BEA AquaLogic Interaction Plumtree Portal
portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.
network
low complexity
bea
5.0
2007-12-01 CVE-2007-6197 Information Exposure vulnerability in BEA Aqualogic Interaction
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
network
low complexity
bea CWE-200
5.0