The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_server | Bea | 9.2 | 9.2 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.2 | 9.2 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.1 | 9.1 |
Weblogic_server | Bea | 10.0 | 10.0 |
Weblogic_server | Bea | 9.2 | 9.2 |
Weblogic_server | Bea | 9.0 | 9.0 |
Weblogic_server | Bea | 9.1 | 9.1 |