The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2007-05-09T22:00:00
Updated: 2024-08-07T13:13:41.699Z
Reserved: 2007-04-04T00:00:00
Link: CVE-2007-1858
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-05-10T00:19:00.000
Modified: 2023-02-13T02:17:34.043
Link: CVE-2007-1858
Redhat