Vulnerability Name:

CVE-2007-4613 (CCN-31558)

Assigned:2007-01-16
Published:2007-01-16
Updated:2018-10-26
Summary:SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the elapsed time before an error response, a different vulnerability than CVE-2006-2461.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2007-4613

Source: BEA
Type: Patch, Vendor Advisory
BEA07-134.00

Source: OSVDB
Type: Broken Link
45838

Source: CCN
Type: OSVDB ID: 45838
BEA WebLogic Server SSL MitM Plaintext Information Disclosure

Source: BID
Type: Patch, Third Party Advisory, VDB Entry
22082

Source: CCN
Type: BID-22082
BEA Multiple Products Multiple Vulnerabilities

Source: XF
Type: UNKNOWN
weblogic-ssl-mitm(31558)

Source: CCN
Type: BEA07-134.00
SSL libraries may be vulnerable to unauthorized information disclosure

Vulnerable Configuration:Configuration 1:
  • cpe:/a:bea:weblogic_server:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
  • OR cpe:/a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    bea weblogic server 6.0
    bea weblogic server 6.1 sp1
    bea weblogic server 6.1 sp2
    bea weblogic server 6.1 sp3
    bea weblogic server 6.1 sp4
    bea weblogic server 6.1 sp5
    bea weblogic server 6.1 sp6
    bea weblogic server 6.1 sp7
    bea weblogic server 7.0
    bea weblogic server 7.0 sp1
    bea weblogic server 7.0 sp2
    bea weblogic server 7.0 sp3
    bea weblogic server 7.0 sp4
    bea weblogic server 7.0 sp5
    bea weblogic server 7.0 sp6
    bea weblogic server 7.0 sp7
    bea weblogic server 8.1
    bea weblogic server 8.1 sp1
    bea weblogic server 8.1 sp2
    bea weblogic server 8.1 sp3
    bea weblogic server 8.1 sp4
    bea weblogic server 8.1 sp5