5.8

CVE-2008-0898

The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.

Data is provided by the National Vulnerability Database (NVD)
BeaWeblogic Server Version9.0
BeaWeblogic Server Version9.0 Updatega
BeaWeblogic Server Version9.0 Updatesp1
BeaWeblogic Server Version9.0 Updatesp2
BeaWeblogic Server Version9.0 Updatesp3
BeaWeblogic Server Version9.0 Updatesp4
BeaWeblogic Server Version9.0 Updatesp5
BeaWeblogic Server Version9.1
BeaWeblogic Server Version9.1 Updatega
BeaWeblogic Server Version9.2
BeaWeblogic Server Version9.2 Updatemp1
BeaWeblogic Server Version9.2 Updatemp2
BeaWeblogic Server Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.426
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N