CVE-2007-2701: Medium severity Bea WebLogic Server vulnerability
The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and "send unauthorized messages to a protected queue."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2701?
CVE-2007-2701 is considered a critical vulnerability due to its ability to allow unauthorized message access.
How do I fix CVE-2007-2701?
To mitigate CVE-2007-2701, ensure the JMS Message Bridge is configured with a valid username and password and define the connection URL.
What is the impact of CVE-2007-2701 on BEA WebLogic Server?
CVE-2007-2701 allows remote attackers to bypass security policies and send unauthorized messages, compromising system integrity.
Which versions of WebLogic Server are affected by CVE-2007-2701?
CVE-2007-2701 affects BEA WebLogic Server versions 7.0 through SP7 and versions 8.1 through Service Pack 6.
Can I exploit CVE-2007-2701 without authentication?
Yes, CVE-2007-2701 allows exploitation without authentication if the JMS Message Bridge is incorrectly configured.