CVE-2007-5281

UnknownEPSS 2.20%

Last modified

CVE-2007-5281 is a vulnerability of currently unknown severity. The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as CVE-2007-3698.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.

Description

The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as CVE-2007-3698.

Metrics

EPSS Probability
2.20%

80.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HitachiUcosminexus Application Server Enterprise07_50
HitachiUcosminexus Application Server Standard7_50
HitachiUcosminexus Client07_50
HitachiUcosminexus Developer Professional07_50
HitachiUcosminexus Developer Standard07_50
HitachiUcosminexus Operator07_50
HitachiUcosminexus Service Architect7_50
HitachiUcosminexus Service Platform7_50

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-5281?
The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as CVE-2007-3698.
How severe is CVE-2007-5281?
Severity scoring for CVE-2007-5281 is pending analysis. The EPSS model estimates a 2.20% probability of exploitation in the next 30 days.
How do I fix CVE-2007-5281?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-5281?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST