← All CVEs

CVE-2007-1858

low · 2.6

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

2.6
CVSS
18.3%
EPSS (exploit prob.)
97th
EPSS percentile
2007-05-10
Published

AV:N/AC:H/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
apachetomcat4.1.28
apachetomcat4.1.31
apachetomcat5.0.0
apachetomcat5.0.1
apachetomcat5.0.2
apachetomcat5.0.10
apachetomcat5.0.11
apachetomcat5.0.12
apachetomcat5.0.13
apachetomcat5.0.14
apachetomcat5.0.15
apachetomcat5.0.16
apachetomcat5.0.17
apachetomcat5.0.18
apachetomcat5.0.19
apachetomcat5.0.21
apachetomcat5.0.22
apachetomcat5.0.23
apachetomcat5.0.24
apachetomcat5.0.25
apachetomcat5.0.26
apachetomcat5.0.27
apachetomcat5.0.28
apachetomcat5.0.29
apachetomcat5.0.30
apachetomcat5.5.0
apachetomcat5.5.1
apachetomcat5.5.2
apachetomcat5.5.3
apachetomcat5.5.4
apachetomcat5.5.5
apachetomcat5.5.6
apachetomcat5.5.7
apachetomcat5.5.8
apachetomcat5.5.9
apachetomcat5.5.10
apachetomcat5.5.11
apachetomcat5.5.12
apachetomcat5.5.13
apachetomcat5.5.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1858