CVE-2007-2701
The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and…
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and "send unauthorized messages to a protected queue."
- CVSS 2.0
- 4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/234Patch, Vendor Advisory
- http://osvdb.org/36067
- http://secunia.com/advisories/25284Vendor Advisory
- http://securitytracker.com/id?1018057Patch
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34287
- http://dev2dev.bea.com/pub/advisory/234Patch, Vendor Advisory
- http://osvdb.org/36067
- http://secunia.com/advisories/25284Vendor Advisory
- http://securitytracker.com/id?1018057Patch
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34287
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.