PT-2008-2512 · Bea · Bea Weblogic Server
Published
2008-02-22
·
Updated
2011-03-08
·
CVE-2008-0898
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 9.0 through 10.0
Description
The distributed queue feature in JMS does not properly handle when a client cannot send a message to a member of a distributed queue, allowing remote authenticated users to bypass intended access restrictions for protected distributed queues.
Recommendations
For BEA WebLogic Server versions 9.0 through 10.0, consider restricting access to the distributed queue feature until a proper fix is applied to handle client message sending failures. As a temporary workaround, review and adjust the configurations to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bea Weblogic Server