PT-2007-4013 · Bea · Bea Weblogic Server

Publicado

2007-05-16

·

Atualizado

2017-07-29

·

CVE-2007-2696

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 6.1 through SP7 BEA WebLogic Server versions 7.0 through SP6 BEA WebLogic Server versions 8.1 through SP5
Description The issue concerns the JMS Server in BEA WebLogic Server, where security access policies are enforced on the front end. This allows remote attackers to access protected queues by making direct requests to the JMS back-end server.
Recommendations For BEA WebLogic Server versions 6.1 through SP7, consider restricting direct access to the JMS back-end server to prevent exploitation. For BEA WebLogic Server versions 7.0 through SP6, restrict direct access to the JMS back-end server to minimize the risk of unauthorized queue access. For BEA WebLogic Server versions 8.1 through SP5, limit direct requests to the JMS back-end server as a temporary mitigation measure until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2696

Produtos afetados

Bea Weblogic Server