CVE-2007-4613

S

SL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the elapsed time before an error response, a different vulnerability than CVE-2006-2461.

References
Link Resource
http://dev2dev.bea.com/pub/advisory/201 Patch Vendor Advisory
http://osvdb.org/45838 Broken Link
http://www.securityfocus.com/bid/22082 Patch Third Party Advisory VDB Entry
http://dev2dev.bea.com/pub/advisory/201 Patch Vendor Advisory
http://osvdb.org/45838 Broken Link
http://www.securityfocus.com/bid/22082 Patch Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*

History

21 Nov 2024, 00:36

Type Values Removed Values Added
References () http://dev2dev.bea.com/pub/advisory/201 - Patch, Vendor Advisory () http://dev2dev.bea.com/pub/advisory/201 - Patch, Vendor Advisory
References () http://osvdb.org/45838 - Broken Link () http://osvdb.org/45838 - Broken Link
References () http://www.securityfocus.com/bid/22082 - Patch, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/22082 - Patch, Third Party Advisory, VDB Entry

Information

Published : 2007-08-31 00:17

Updated : 2025-04-09 00:30


NVD link : CVE-2007-4613

Mitre link : CVE-2007-4613

CVE.ORG link : CVE-2007-4613


JSON object : View

Products Affected
CWE
CWE-310

Cryptographic Issues