CVE-2007-2696

high

Description

The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/34284

http://www.vupen.com/english/advisories/2007/1815

http://securitytracker.com/id?1018057

http://secunia.com/advisories/25284

http://osvdb.org/36073

http://dev2dev.bea.com/pub/advisory/228

Details

Source: Mitre, NVD

Published: 2007-05-16

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00897