CVE-2007-4615
Estado: ModificadaMedia (6.4)—
The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.13%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://dev2dev.bea.com/pub/advisory/244
- http://secunia.com/advisories/26539
- http://securitytracker.com/id?1018619
- http://www.securityfocus.com/bid/25472
- http://www.vupen.com/english/advisories/2007/3008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36322
- http://dev2dev.bea.com/pub/advisory/244
- http://secunia.com/advisories/26539
- http://securitytracker.com/id?1018619
- http://www.securityfocus.com/bid/25472
- http://www.vupen.com/english/advisories/2007/3008
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36322
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4615",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-08-31T00:17:00.000",
"references": [
{
"url": "http://dev2dev.bea.com/pub/advisory/244",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26539",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018619",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25472",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3008",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36322",
"source": "cve@mitre.org"
},
{
"url": "http://dev2dev.bea.com/pub/advisory/244",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26539",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018619",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25472",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3008",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36322",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications."
},
{
"lang": "es",
"value": "La implementación del cliente SSL en el BEA WebLogic Server 7.0 SP7, el 8.1 SP2 hasta el SP6, el 9.0, el 9.1, el 9.2 Gold hasta el MP2 y el 10.0, selecciona algunas veces una clave nula cuando otras están habilitadas, lo que puede permitir a atacantes remotos interceptar las comunicaciones."
}
],
"lastModified": "2026-06-16T22:44:26.293",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bea:weblogic_server:*:mp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2A3768A-527C-4CDA-A544-E34AD84D8B8A",
"versionEndIncluding": "9.2"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5D61A68-E83A-4374-832A-C9A2FEA0AD6C"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D18E22CC-A0FC-4BC7-AD39-2645F57486C1"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9429D939-FCC4-4BA7-90C4-BBEECE7309D0"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0653ACAC-B0D9-4381-AB23-11D24852A414"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A489A8E-D3AE-42DF-8DCF-5A9EF10778FA"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A75A7F9-A99A-4C8E-9867-71FA8A55DD70"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CA97F1A-49F7-4511-8959-D62155491DF5"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCAAE8F1-CB25-4871-BE48-ABF7DFAD8AD6"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60F9ABCC-5217-4650-8C71-F8B0EB86789F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}