CVE-2007-4615
Last modified
CVE-2007-4615 is a vulnerability of currently unknown severity. The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Bea | Weblogic Server | <= 9.2 | Mp2 |
| Bea | Weblogic Server | 7.0 | Sp7 |
| Bea | Weblogic Server | 8.1 | Sp2 |
| Bea | Weblogic Server | 9.0 | — |
| Bea | Weblogic Server | 9.1 | — |
| Bea | Weblogic Server | 10.0 | — |
References
- http://secunia.com/advisories/26539Patch, Vendor Advisory
- http://secunia.com/advisories/26539Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4615?
How severe is CVE-2007-4615?
How do I fix CVE-2007-4615?
Are you affected by CVE-2007-4615?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
