CVE-2007-2696: Medium severity Bea WebLogic Server vulnerability
The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2696?
The severity of CVE-2007-2696 is considered critical due to its potential for unauthorized access to protected JMS queues.
How do I fix CVE-2007-2696?
To fix CVE-2007-2696, update your BEA WebLogic Server to a version that is not vulnerable, specifically beyond SP7 for versions 6.1, beyond SP6 for version 7.0, and beyond SP5 for version 8.1.
What systems are affected by CVE-2007-2696?
CVE-2007-2696 affects BEA WebLogic Server versions 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5.
What types of attacks are possible with CVE-2007-2696?
Attackers can exploit CVE-2007-2696 to remotely access and manage protected JMS queues by bypassing security policies.
Is there a workaround for CVE-2007-2696 while waiting for a patch?
While an official workaround is not specified, restricting access to the JMS server and implementing additional network security measures can help mitigate risks.