CVE-2008-0897: High severity oracle weblogic server vulnerability
Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0897?
CVE-2008-0897 is considered a high severity vulnerability due to its ability to allow unauthorized message access.
How do I fix CVE-2008-0897?
To fix CVE-2008-0897, update to a non-vulnerable version of BEA WebLogic Server, such as version 10.3.5 or later.
Who is affected by CVE-2008-0897?
CVE-2008-0897 affects BEA WebLogic Server versions 9.0 through 10.0, along with specific minor updates.
What kind of attack leverages CVE-2008-0897?
CVE-2008-0897 can be exploited by remote authenticated users to bypass access restrictions and receive messages from JMS Topics.
Is CVE-2008-0897 a local or remote vulnerability?
CVE-2008-0897 is a remote vulnerability that requires authentication to exploit.