CVE-2007-5281
The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain…
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as CVE-2007-3698.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- hitachi/ucosminexus application server enterprise · hitachi/ucosminexus application server standard · hitachi/ucosminexus client · hitachi/ucosminexus developer professional · hitachi/ucosminexus developer standard · hitachi/ucosminexus operator · hitachi/ucosminexus service architect · hitachi/ucosminexus service platform
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/27075Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-031_e/index-e.html
- http://www.securityfocus.com/bid/25935
- http://www.vupen.com/english/advisories/2007/3375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36965
- http://secunia.com/advisories/27075Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-031_e/index-e.html
- http://www.securityfocus.com/bid/25935
- http://www.vupen.com/english/advisories/2007/3375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36965
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.