#VU86 Man-in-the-middle attack in Sun products - CVE-2015-4000

 

#VU86 Man-in-the-middle attack in Sun products - CVE-2015-4000

Published: July 4, 2016 / Updated: November 8, 2022


Vulnerability identifier: #VU86
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2015-4000
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
HPE Service Manager
Oracle Solaris
Oracle Directory Server Enterprise Edition
Oracle GlassFish Server
Oracle OpenSSO
Oracle Traffic Director
Sun ONE/iPlanet Web Server
SPARC Enterprise M3000
SPARC Enterprise M4000
SPARC Enterprise M5000
SPARC Enterprise M8000
SPARC Enterprise M9000
Oracle Secure Global Desktop
Software vendor:
Hewlett Packard Enterprise Development LP
Oracle
Sun

Description

The vulnerability allows a remote attacker to decrypt TLS connections in certain situations.

The vulnerability exists due to boundary error when parsing HTTP requests. A remote unauthenticated attacker can conduct a man-in-the-middle attack that can lead to the target system to downgrade the Diffie-Hellman algorithm to 512-bit export-grade cryptography.

Successful exploitation of this vulnerability may result in modification of authentication information

Remediation


External links