Java Secure Socket Extension Does Not Correctly Process SSL/TLS Handshake Requests Resulting in a Denial of Service (DoS) Condition
Published Jul 11, 2007
7.8
HIGHCVSS 2.0
EPSS 3.82%
Description
The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.
Affected products
No data.
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
No data.
Extras for RHEL 3
java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3
Fixed · RHSA-2008:0100
Extras for RHEL 3
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4
Fixed · RHSA-2007:1086
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.5.0-sun-0:1.5.0.12-1jpp.2.el4
Fixed · RHSA-2007:0818
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5
Fixed · RHSA-2008:0100
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5
Fixed · RHSA-2008:0132
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5
Fixed · RHSA-2007:0956
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3 | Fixed | RHSA-2008:0100 |
| Extras for RHEL 3 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4 | Fixed | RHSA-2007:1086 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.5.0-sun-0:1.5.0.12-1jpp.2.el4 | Fixed | RHSA-2007:0818 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5 | Fixed | RHSA-2008:0100 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5 | Fixed | RHSA-2008:0132 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5 | Fixed | RHSA-2007:0956 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.82% (0.03822) | 89.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.82% (0.03822) | 88.66th | v5 (v2026.06.15) |
| Apr 5, 2026 | 19.04% (0.19037) | 95.31th | v4 (v2025.03.14) |
| Mar 30, 2025 | 16.80% (0.16804) | 94.39th | v4 (v2025.03.14) |
| Mar 29, 2025 | 27.07% (0.27073) | 94.20th | v4 (v2025.03.14) |
| Mar 19, 2025 | 16.80% (0.16804) | 94.15th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.30% (0.09297) | 92.16th | v4 (v2025.03.14) |
| Dec 17, 2024 | 24.16% (0.24162) | 96.62th | v3 (v2023.03.01) |
| Sep 5, 2024 | 45.67% (0.45668) | 97.50th | v3 (v2023.03.01) |
| Jul 29, 2024 | 50.02% (0.50024) | 97.56th | v3 (v2023.03.01) |
| Jun 21, 2024 | 44.95% (0.44947) | 97.42th | v3 (v2023.03.01) |
| May 14, 2024 | 30.36% (0.30356) | 96.92th | v3 (v2023.03.01) |
| Apr 6, 2024 | 31.71% (0.31714) | 96.91th | v3 (v2023.03.01) |
| Feb 28, 2024 | 32.86% (0.32859) | 96.89th | v3 (v2023.03.01) |
| Dec 13, 2023 | 23.23% (0.23234) | 96.08th | v3 (v2023.03.01) |
| Jul 17, 2023 | 18.60% (0.18603) | 95.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 17.48% (0.17480) | 95.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
No CWE recorded.
References (44)
- http://dev2dev.bea.com/pub/advisory/249 vendor-advisoryx_refsource_BEA
- http://docs.info.apple.com/article.html?artnum=307177 x_refsource_MISC
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450 vendor-advisoryx_refsource_HP
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/36663 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/26015 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26221 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26314 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26631 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26645 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26933 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27203 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27635 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27716 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28056 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28115 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28777 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28880 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29340 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29897 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1 vendor-advisoryx_refsource_SUNALERTPatchVendor Advisory
- http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html x_refsource_CONFIRM
- http://www.cisco.com/en/US/products/products_security_response09186a008088bd19.html vendor-advisoryx_refsource_CISCOVendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sr-20070725-jsse.shtml x_refsource_CONFIRMVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200709-15.xml vendor-advisoryx_refsource_GENTOO
- http://www.redhat.com/support/errata/RHSA-2007-0818.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-0956.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1086.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0100.html vendor-advisoryx_refsource_REDHATPatch
- http://www.redhat.com/support/errata/RHSA-2008-0132.html vendor-advisoryx_refsource_REDHATPatch
- http://www.securityfocus.com/bid/24846 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1018357 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2007/2495 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/2660 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/3009 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/3861 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/4224 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2007-3698 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=249539 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35333 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-3698
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10634 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-3698
Change history (0)
No recorded changes yet.