Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.
| Software | From | Fixed in |
|---|---|---|
| bea_systems / plumtree_collaboration | 4.1_sp2 | 4.1_sp2.x |
| bea_systems / aqualogic_interaction | 4.2 | 4.2.x |
| bea_systems / plumtree_collaboration | 4.1_sp1 | 4.1_sp1.x |
| bea_systems / plumtree_collaboration | 4.1 | 4.1.x |
| bea_systems / aqualogic_interaction | 4.2_mp1 | 4.2_mp1.x |