Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-4511

EPSS 0.80% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-4511

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sun Java系统应用服务器管理控制台加密协议选择漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sun Java系统应用服务器是与J2EE平台兼容的应用服务器。 Sun应用服务器处理SSL的设置时存在漏洞,远程攻击者可能利用此漏洞非授权访问应用系统。 Sun服务器使用Sun管理控制台控制和更改SSL密码,而通过管理用户界面更改ORB监听程序(SSL和SSL_MutualAuth)不能确保在软件中也做了相应的更改,在重启服务/域后所有的SSL设置仍为默认,也就是允许所有协议和密码。这意味着无论在应用服务器的SUN管理用户界面做了何种选择,都不会影响SSL设置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-4511

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-4511

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-08-23 · 22 CVEs total

CVE-2007-4501SSHKeychain PassphraseRequester 敏感信息泄露漏洞
CVE-2007-3847Apache HTTP Server 安全漏洞
CVE-2007-4510ClamAV多个拒绝服务漏洞
CVE-2007-4509Joomla! EventList 组件'index.php'SQL注入漏洞
CVE-2007-4508Asura引擎挑战B查询远程栈缓冲区溢出漏洞
CVE-2007-4507PHP php_ntuser组件多个缓冲区溢出漏洞
CVE-2007-4506Joomla! NeoRecruit 组件'index.php'SQL注入漏洞
CVE-2007-4505Mambo RemoSitory 组件'index.php'SQL注入漏洞
CVE-2007-4504Joomla! RSfiles 组件'index.php'目录遍历漏洞
CVE-2007-4503Joomla! Nice Talk 组件'index.php'SQL注入漏洞
CVE-2007-4502Joomla! BibTeX 组件'index.php'SQL注入漏洞
CVE-2007-4491Gurer haber'uyeler2.php' SQL注入漏洞
CVE-2007-4500SSHKeychain TunnelRunner本地权限提升及信息泄露漏洞
CVE-2007-4499American Financing eMail Image Upload'output.php' 任意文件上传漏洞
CVE-2007-4498Grandstream GXV-3000电话远程拒绝服务漏洞
CVE-2007-4495Sun Solaris ATA磁盘驱动IOCTL本地拒绝服务漏洞
CVE-2007-4494eZ Publish tipafriend函数 公开邮件转播漏洞
CVE-2007-4493eZ Publish 政策函数的模块检测缺失漏洞
CVE-2003-1335Kai Blankenhorn Bitfolge简单且精密的索引文件 (又称为snif)在snif目录上从本地下载文件漏洞
CVE-2003-1334Kai Blankenhorn Bitfolge simple and nice index file (aka snif)跨站脚本漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-4511

No comments yet


Leave a comment