PT-2015-1091 · Ibm+5 · Ssl/Tls+7

Published

2015-04-14

·

Updated

2024-06-15

·

CVE-2015-0477

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40 IBM SSL/TLS implementations (affected versions not specified)
Description The issue affects the integrity of data and is related to the Beans component in Oracle Java SE, allowing remote attackers to exploit it via unknown vectors. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections using man-in-the-middle techniques, facilitating brute-force decryption of TLS/SSL traffic.
Recommendations For Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40, consider disabling the Beans component as a temporary workaround until a patch is available. For IBM SSL/TLS implementations, restrict the use of RSA temporary keys in non-export RSA key exchange ciphersuites to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09957
CESA-2015_0806
CESA-2015_0808
CESA-2015_0809
CVE-2015-0477
DLA-213-1
DSA-3234-1
DSA-3235-1
DSA-3316-1
MGASA-2015-0158
OPENSUSE-SU-2015_0773-1
OPENSUSE-SU-2015_0774-1
OPENSUSE-SU-2024:10534-1
RHSA-2015:0806
RHSA-2015:0807
RHSA-2015:0808
RHSA-2015:0809
RHSA-2015:0854
RHSA-2015:0857
RHSA-2015:0858
RHSA-2015:1006
RHSA-2015:1007
RHSA-2015:1020
RHSA-2015:1021
RHSA-2015:1091
RHSA-2015_0806
RHSA-2015_0807
RHSA-2015_0808
RHSA-2015_0809
RHSA-2015_0854
RHSA-2015_0857
RHSA-2015_0858
RHSA-2015_1006
RHSA-2015_1020
RHSA-2015_1021
SUSE-SU-2015:0789-1
SUSE-SU-2015:1161-1
SUSE-SU-2015:2166-1
SUSE-SU-2015:2168-1
SUSE-SU-2015:2168-2
SUSE-SU-2015:2182-1
SUSE-SU-2015:2192-1
SUSE-SU-2015:2216-1
USN-2573-1
USN-2574-1

Affected Products

Centos
Ibm Aix
Java Platform
Java Se
Red Hat
Ssl/Tls
Suse
Ubuntu