HomeBeaCVE-2007-2701

CVE-2007-2701

UNKNOWN
4.6CVSS
Published: 2007-05-16
Updated: 2025-04-09
AI Analysis

Description

The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and "send unauthorized messages to a protected queue."

CVSS Metrics

Vector
AV:N/AC:H/Au:S/C:P/I:P/A:P
Access Vector
network
Access Cmplx
high
Auth
single
Confidentiality
partial
Integrity
partial
Availability
partial
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
BEA
Published
5/16/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

bea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-2701 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com