Vulnerability Name: | CVE-2007-4613 (CCN-31558) | ||||||||
Assigned: | 2007-01-16 | ||||||||
Published: | 2007-01-16 | ||||||||
Updated: | 2018-10-26 | ||||||||
Summary: | SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the elapsed time before an error response, a different vulnerability than CVE-2006-2461. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4613 Source: BEA Type: Patch, Vendor Advisory BEA07-134.00 Source: OSVDB Type: Broken Link 45838 Source: CCN Type: OSVDB ID: 45838 BEA WebLogic Server SSL MitM Plaintext Information Disclosure Source: BID Type: Patch, Third Party Advisory, VDB Entry 22082 Source: CCN Type: BID-22082 BEA Multiple Products Multiple Vulnerabilities Source: XF Type: UNKNOWN weblogic-ssl-mitm(31558) Source: CCN Type: BEA07-134.00 SSL libraries may be vulnerable to unauthorized information disclosure | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |