CVE-2008-0898
22.02.2008, 21:44
The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.Enginsight
Vendor | Product | Version |
---|---|---|
bea | weblogic_server | 9.0 |
bea | weblogic_server | 9.0:ga |
bea | weblogic_server | 9.0:sp1 |
bea | weblogic_server | 9.0:sp2 |
bea | weblogic_server | 9.0:sp3 |
bea | weblogic_server | 9.0:sp4 |
bea | weblogic_server | 9.0:sp5 |
bea | weblogic_server | 9.1 |
bea | weblogic_server | 9.1:ga |
bea | weblogic_server | 9.2 |
bea | weblogic_server | 9.2:mp1 |
bea | weblogic_server | 9.2:mp2 |
bea | weblogic_server | 10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References