CVE-2008-0897

Published Feb 22, 2008

Last updated a month ago

Overview

Description
Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.
Source
cve@mitre.org
NVD status
Deferred

Risk scores

CVSS 2.0

Type
Primary
Base score
7.9
Impact score
9.2
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:C/I:C/A:N

Weaknesses

nvd@nist.gov
CWE-264

Social media

Hype score
Not currently trending

Configurations