PT-2015-1091 · Ibm+5 · Ssl/Tls+7
Publicado
2015-04-14
·
Atualizado
2024-06-15
·
CVE-2015-0477
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40
IBM SSL/TLS implementations (affected versions not specified)
Description
The issue affects the integrity of data and is related to the Beans component in Oracle Java SE, allowing remote attackers to exploit it via unknown vectors. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections using man-in-the-middle techniques, facilitating brute-force decryption of TLS/SSL traffic.
Recommendations
For Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40, consider disabling the Beans component as a temporary workaround until a patch is available.
For IBM SSL/TLS implementations, restrict the use of RSA temporary keys in non-export RSA key exchange ciphersuites to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Ibm Aix
Java Platform
Java Se
Red Hat
Ssl/Tls
Suse
Ubuntu