CVE-2007-3698: High severity Java Development Kit (JDK) vulnerability

Published Jul 11, 2007
·
Updated

The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.211 through 1.4.214, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.

Affected Software

20 affected components
Java Development Kit (JDK)=1.5.0-update10
Java Development Kit (JDK)=1.5.0-update11
Java Development Kit (JDK)=1.5.0-update7
Java Development Kit (JDK)=1.5.0-update8
Java Development Kit (JDK)=1.5.0-update9
Java Development Kit (JDK)=1.6.0-update1
Sun Java Runtime Environment (JRE)=1.4.2_11
Sun Java Runtime Environment (JRE)=1.4.2_12
Sun Java Runtime Environment (JRE)=1.4.2_13
Sun Java Runtime Environment (JRE)=1.4.2_14
Sun Java Runtime Environment (JRE)=1.5.0-update10
Sun Java Runtime Environment (JRE)=1.5.0-update11
Sun Java Runtime Environment (JRE)=1.5.0-update7
Sun Java Runtime Environment (JRE)=1.5.0-update8
Sun Java Runtime Environment (JRE)=1.5.0-update9
Sun Java Runtime Environment (JRE)=1.6.0-update_1
Sun SDK=1.4.2_11
Sun SDK=1.4.2_12
Sun SDK=1.4.2_13
Sun SDK=1.4.2_14

Event History

Jul 11, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-3698?

CVE-2007-3698 is classified as a denial of service vulnerability that can lead to high CPU consumption.

2

How do I fix CVE-2007-3698?

The recommended fix for CVE-2007-3698 is to upgrade to a patched version of the Java platform that addresses this vulnerability.

3

Which versions are affected by CVE-2007-3698?

CVE-2007-3698 affects specific versions of Sun JDK and JRE, including versions 1.4.2_11 to 1.4.2_14 and 1.6.0 Update 1 and earlier.

4

What impact does CVE-2007-3698 have on applications?

CVE-2007-3698 can cause affected applications to become unresponsive due to excessive CPU load during SSL/TLS handshaking.

5

Who can exploit CVE-2007-3698?

Remote attackers can exploit CVE-2007-3698 to trigger the denial of service condition by initiating specially crafted SSL/TLS handshakes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203