The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Java_system_application_server | Sun | 9.0_0.1 (including) | 9.0_0.1 (including) |