Vulnerability Name:
CVE-2007-1858 (CCN-34212)
Assigned:
2007-05-09
Published:
2007-05-09
Updated:
2023-02-13
Summary:
CVSS v3 Severity:
7.3 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
2.6 Low
(CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N
)
1.9 Low
(Temporal CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
7.5 High
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
)
5.5 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Consequences:
Bypass Security
References:
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: CA Security Response Blog, Jan 23 2009, 06:04 PM
CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities
Source: MITRE
Type: CNA
CVE-2007-1858
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: RHSA-2007-0326
Important: tomcat security update
Source: CCN
Type: RHSA-2007-0340
Important: tomcat security update
Source: CCN
Type: RHSA-2007-1069
Moderate: tomcat security update for Red Hat Network Satellite Server
Source: CCN
Type: SA33668
CA Cohesion Application Configuration Manager Apache Tomcat Multiple Vulnerabilities
Source: CCN
Type: SA40425
Novell ZENworks Linux Management Tomcat Multiple Vulnerabilities
Source: CCN
Type: SA44183
BlackBerry Enterprise Server Multiple Vulnerabilities
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: ASA-2007-206
tomcat security update (RHSA-2007-0326)
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: Apache Tomcat Web site
Apache Tomcat 4.x vulnerabilities
Source: secalert@redhat.com
Type: Patch
secalert@redhat.com
Source: secalert@redhat.com
Type: Patch
secalert@redhat.com
Source: CCN
Type: Novell Document ID: 7006398
Tomcat 5.0.28 in ZLM 7.3 subject to "Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities"
Source: CCN
Type: Oracle Web site
Oracle Critical Patch Update Advisory - January 2014
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: OSVDB ID: 34882
Apache Tomcat Default SSL Ciphersuite Configuration Weakness
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: BID-28482
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: BID-64758
RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: XF
Type: UNKNOWN
tomcat-ssl-security-bypass(34212)
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com
Source: CCN
Type: CA20090123-01
Security Notice for Cohesion Tomcat
Source: SUSE
Type: SUSE-SR:2008:007
SUSE Security Summary Report
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/a:apache:tomcat:5.5.4:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.19:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.28:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.7:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.25:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.17:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.0:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:4.1.28:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:4.1.31:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.1:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.13:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.14:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.15:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.16:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.17:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.18:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.2:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.21:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.22:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.23:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.24:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.26:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.27:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.29:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.0.30:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.0:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.1:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.13:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.14:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.15:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.16:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.2:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.3:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.5:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.6:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.8:*:*:*:*:*:*:*
AND
cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
OR
cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
OR
cpe:/a:redhat:rhel_application_server:2:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20071858
V
CVE-2007-1858
2015-11-16
BACK
apache
tomcat 5.5.4
apache
tomcat 5.0.19
apache
tomcat 5.0.28
apache
tomcat 5.5.12
apache
tomcat 5.5.9
apache
tomcat 5.5.7
apache
tomcat 5.0.25
apache
tomcat 5.5.17
apache
tomcat 5.0.0
apache
tomcat 4.1.28
apache
tomcat 4.1.31
apache
tomcat 5.0.1
apache
tomcat 5.0.10
apache
tomcat 5.0.11
apache
tomcat 5.0.12
apache
tomcat 5.0.13
apache
tomcat 5.0.14
apache
tomcat 5.0.15
apache
tomcat 5.0.16
apache
tomcat 5.0.17
apache
tomcat 5.0.18
apache
tomcat 5.0.2
apache
tomcat 5.0.21
apache
tomcat 5.0.22
apache
tomcat 5.0.23
apache
tomcat 5.0.24
apache
tomcat 5.0.26
apache
tomcat 5.0.27
apache
tomcat 5.0.29
apache
tomcat 5.0.30
apache
tomcat 5.5.0
apache
tomcat 5.5.1
apache
tomcat 5.5.10
apache
tomcat 5.5.11
apache
tomcat 5.5.13
apache
tomcat 5.5.14
apache
tomcat 5.5.15
apache
tomcat 5.5.16
apache
tomcat 5.5.2
apache
tomcat 5.5.3
apache
tomcat 5.5.5
apache
tomcat 5.5.6
apache
tomcat 5.5.8
redhat
enterprise linux 3
redhat
enterprise linux 4
redhat
linux advanced workstation 2.1
redhat
enterprise linux 5
redhat
rhel application server 2