CVE-2006-5654: Medium severity sun Java System Web Server vulnerability
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5654?
CVE-2006-5654 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2006-5654?
To fix CVE-2006-5654, disable SSLv2 on the affected versions of Sun Java System Web Server and Sun ONE Application Server.
Which versions of software are affected by CVE-2006-5654?
CVE-2006-5654 affects Sun Java System Web Server 6.0 before SP 10 and Sun ONE Application Server 7 before Update 3.
Can CVE-2006-5654 be exploited remotely?
Yes, CVE-2006-5654 can be exploited by remote authenticated users to cause a denial of service.
Is there a workaround for CVE-2006-5654?
A temporary workaround for CVE-2006-5654 is to disable SSLv2 if immediate patching is not feasible.