CVE-2008-0898: Medium severity oracle weblogic server vulnerability
The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0898?
CVE-2008-0898 is classified as a medium severity vulnerability that allows remote authenticated users to bypass access restrictions.
How do I fix CVE-2008-0898?
To fix CVE-2008-0898, upgrade to a patched version of BEA WebLogic Server, such as any release after version 10.0.
Which versions of BEA WebLogic Server are affected by CVE-2008-0898?
CVE-2008-0898 affects BEA WebLogic Server versions 9.0 through 10.0.
What impact does CVE-2008-0898 have on affected systems?
CVE-2008-0898 can allow remote authenticated users to bypass intended access restrictions for protected distributed queues.
Are there workarounds for CVE-2008-0898?
The primary mitigation for CVE-2008-0898 is to upgrade to a version of BEA WebLogic Server that is not vulnerable.