CVE-2007-4616
Last modified
CVE-2007-4616 is a vulnerability of currently unknown severity. The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote attackers to intercept communications.. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote attackers to intercept communications.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bea | Weblogic Server | 7.0 |
| Bea | Weblogic Server | 8.1 |
| Bea | Weblogic Server | 9.0 |
| Bea | Weblogic Server | 9.1 |
| Bea | Weblogic Server | 9.2 |
| Bea | Weblogic Server | 10.0 |
References
- http://secunia.com/advisories/26539Patch, Vendor Advisory
- http://securitytracker.com/id?1018620Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25472Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3008Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36320Third Party Advisory, VDB Entry
- http://secunia.com/advisories/26539Patch, Vendor Advisory
- http://securitytracker.com/id?1018620Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25472Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3008Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36320Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4616?
How severe is CVE-2007-4616?
How do I fix CVE-2007-4616?
Are you affected by CVE-2007-4616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
