PT-2008-2512 · Bea · Bea Weblogic Server

Publicado

2008-02-22

·

Atualizado

2011-03-08

·

CVE-2008-0898

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 9.0 through 10.0
Description The distributed queue feature in JMS does not properly handle when a client cannot send a message to a member of a distributed queue, allowing remote authenticated users to bypass intended access restrictions for protected distributed queues.
Recommendations For BEA WebLogic Server versions 9.0 through 10.0, consider restricting access to the distributed queue feature until a proper fix is applied to handle client message sending failures. As a temporary workaround, review and adjust the configurations to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0898

Produtos afetados

Bea Weblogic Server