PT-2007-5687 · Sun · Application Server

Published

2007-08-23

·

Updated

2018-10-15

·

CVE-2007-4511

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Sun Application Server version 9.0 0.1
Description The Sun Admin Console in the affected version does not persistently apply certain configuration changes. This issue affects the SSL and SSL MutualAuth ORB listener services, causing them to enable all protocols and ciphers after a restart. As a result, remote attackers may be able to bypass the intended security policy.
Recommendations For Sun Application Server version 9.0 0.1, manually reapply the desired configuration changes to the SSL and SSL MutualAuth ORB listener services after each restart to maintain the intended security settings. Consider temporarily disabling the automatic restart of these services until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4511

Affected Products

Application Server