← Back

CVE-2008-0898

nvd nist
Published: Feb 22, 2008Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.

Affected (13)

Products: Bea: Weblogic Server
1 product
Weblogic Server
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Bea
Version 10.0
Version 9.0
Version 9.0 ga
Version 9.0 sp1
Version 9.0 sp2
Version 9.0 sp3
Version 9.0 sp4
Version 9.0 sp5
Version 9.1
Version 9.1 ga
Version 9.2
Version 9.2 mp1
Version 9.2 mp2

Related CWEs

References (8)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.