Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://dev2dev.bea.com/pub/advisory/267 | patch vendor advisory |
http://www.securitytracker.com/id?1019444 | vdb entry |
http://secunia.com/advisories/29041 | third party advisory |
http://www.vupen.com/english/advisories/2008/0612/references | vdb entry |