VulnerabilityModified
CVE-2007-2696
The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server.
MEDIUM 6.8EPSS 2.11%
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/228Patch, Vendor Advisory
- http://osvdb.org/36073
- http://secunia.com/advisories/25284Vendor Advisory
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34284
- http://dev2dev.bea.com/pub/advisory/228Patch, Vendor Advisory
- http://osvdb.org/36073
- http://secunia.com/advisories/25284Vendor Advisory
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34284
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.