SSL/TLS RC4 information leakage (CVE-2015-2808)
SSL/TLS RC4 information leakage (CVE-2015-2808)
Release date:
Updated on:
Affected Systems:
IBM Websphere Application Server 7.x
IBM Websphere Application Server 6.x
Oracle JRockit
Description:
Bugtraq id: 73684
CVE (CAN) ID: CVE-2015-2808
RC4 encryption algorithm is a variable-length stream encryption algorithm cluster, designed by Ron Rivest in 1987.
The RC4 algorithm used in TLS and SSL protocols does not correctly combine state data and keyword data during initialization. This allows remote attackers to perform plain text restoration attacks against the initial bytes of a stream.
<* Source: unknown
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg21883640
Http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
This article permanently updates the link address: