PT-2007-5775 · Bea · Bea Weblogic Server
Published
2007-08-31
·
Updated
2017-07-29
·
CVE-2007-4615
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 7.0 SP7, 8.1 SP2 through 8.1 SP6, 9.0, 9.1, 9.2 Gold through 9.2 MP2, 10.0
Description
The SSL client implementation in the affected software sometimes selects the null cipher when others are available. This could allow remote attackers to intercept communications.
Recommendations
For BEA WebLogic Server version 7.0 SP7, update the SSL client configuration to avoid selecting the null cipher.
For BEA WebLogic Server versions 8.1 SP2 through 8.1 SP6, update the SSL client configuration to avoid selecting the null cipher.
For BEA WebLogic Server versions 9.0, 9.1, 9.2 Gold through 9.2 MP2, 10.0, update the SSL client configuration to avoid selecting the null cipher.
As a temporary workaround, consider disabling the SSL client implementation until a patch is available.
Restrict access to sensitive communications to minimize the risk of interception.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server