CVE-2008-0898

The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
beaweblogic_server
9.0
beaweblogic_server
9.0:ga
beaweblogic_server
9.0:sp1
beaweblogic_server
9.0:sp2
beaweblogic_server
9.0:sp3
beaweblogic_server
9.0:sp4
beaweblogic_server
9.0:sp5
beaweblogic_server
9.1
beaweblogic_server
9.1:ga
beaweblogic_server
9.2
beaweblogic_server
9.2:mp1
beaweblogic_server
9.2:mp2
beaweblogic_server
10.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration