Unrated severityNVD Advisory· Published Aug 31, 2007· Updated Jun 16, 2026
CVE-2007-4616
CVE-2007-4616
Description
The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote attackers to intercept communications.
Affected products
21cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*+ 20 more
- cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
6- dev2dev.bea.com/pub/advisory/245nvdPatch
- secunia.com/advisories/26539nvdPatchVendor Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/25472nvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2007/3008nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/36320nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.