PT-2008-2512 · Bea · Bea Weblogic Server

Published

2008-02-22

·

Updated

2011-03-08

·

CVE-2008-0898

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 9.0 through 10.0
Description The distributed queue feature in JMS does not properly handle when a client cannot send a message to a member of a distributed queue, allowing remote authenticated users to bypass intended access restrictions for protected distributed queues.
Recommendations For BEA WebLogic Server versions 9.0 through 10.0, consider restricting access to the distributed queue feature until a proper fix is applied to handle client message sending failures. As a temporary workaround, review and adjust the configurations to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0898

Affected Products

Bea Weblogic Server