CVE-2007-4511

Sun Application Server 9.0_0.1 - Info Disclosure

Title source: llm

Description

The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.

Scores

EPSS 0.0036
EPSS Percentile 57.4%

Classification

Status draft

Affected Products (1)

sun/java_system_application_server

Timeline

Published Aug 23, 2007
Tracked Since Feb 18, 2026