SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5281

The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain…

MEDIUM 5.0EPSS 2.20%

Does this matter?

Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.

Description

The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as CVE-2007-3698.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
2.20% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
hitachi/ucosminexus application server enterprise · hitachi/ucosminexus application server standard · hitachi/ucosminexus client · hitachi/ucosminexus developer professional · hitachi/ucosminexus developer standard · hitachi/ucosminexus operator · hitachi/ucosminexus service architect · hitachi/ucosminexus service platform
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.