Skip to main content

Use of a Broken or Risky Cryptographic Algorithm

CVE-2007-1858

Severity Low
Score 2.6/10

Summary

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

  • HIGH
  • NETWORK
  • NONE
  • NONE
  • PARTIAL
  • NONE

CWE-327 - Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.

Advisory Timeline

  • Published