PT-2007-5775 · Bea · Bea Weblogic Server

Publicado

2007-08-31

·

Atualizado

2017-07-29

·

CVE-2007-4615

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 7.0 SP7, 8.1 SP2 through 8.1 SP6, 9.0, 9.1, 9.2 Gold through 9.2 MP2, 10.0
Description The SSL client implementation in the affected software sometimes selects the null cipher when others are available. This could allow remote attackers to intercept communications.
Recommendations For BEA WebLogic Server version 7.0 SP7, update the SSL client configuration to avoid selecting the null cipher. For BEA WebLogic Server versions 8.1 SP2 through 8.1 SP6, update the SSL client configuration to avoid selecting the null cipher. For BEA WebLogic Server versions 9.0, 9.1, 9.2 Gold through 9.2 MP2, 10.0, update the SSL client configuration to avoid selecting the null cipher. As a temporary workaround, consider disabling the SSL client implementation until a patch is available. Restrict access to sensitive communications to minimize the risk of interception.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4615

Produtos afetados

Bea Weblogic Server