LWN.net Logo

tomcat: insecure ciphers

Package(s):tomcat CVE #(s):CVE-2007-1858
Created:March 28, 2008 Updated:April 2, 2008
Description: The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
Alerts:
SuSE SUSE-SR:2008:007 2008-03-28

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.