CVE-2007-4511

Sun Application Server 9.0_0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/45828
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25400
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36169
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/477315/100/0/threaded

Scores

EPSS 0.0080
EPSS Percentile 74.2%

Details

Status published
Products (1)
sun/java_system_application_server 9.0_0.1
Published Aug 23, 2007
Tracked Since Feb 18, 2026