PT-2008-2512 · Bea · Bea Weblogic Server
Publicado
2008-02-22
·
Atualizado
2011-03-08
·
CVE-2008-0898
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 9.0 through 10.0
Description
The distributed queue feature in JMS does not properly handle when a client cannot send a message to a member of a distributed queue, allowing remote authenticated users to bypass intended access restrictions for protected distributed queues.
Recommendations
For BEA WebLogic Server versions 9.0 through 10.0, consider restricting access to the distributed queue feature until a proper fix is applied to handle client message sending failures. As a temporary workaround, review and adjust the configurations to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bea Weblogic Server