CVE-2008-0897

EUVD-2008-0904
Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.9 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
beaweblogic_server
9.0
beaweblogic_server
9.1
beaweblogic_server
9.2
beaweblogic_server
9.2:mp1
beaweblogic_server
10.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration