Information disclosure in Hewlett Packard Enterprise Development LP products - CVE-2015-2808

 

Information disclosure in Hewlett Packard Enterprise Development LP products - CVE-2015-2808

Published: July 5, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU90
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2808
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information communicated by target system.

The vulnerability exists due to access control error. A remote unauthenticated attacker can obtain RC4 encrypted data and conduct a brute-force key guessing attack by monitoring TLS network traffic.

Successful exploitation of this vulnerability may result in disclosure of system information.

Affected software

SPARC Enterprise M9000
SPARC Enterprise M8000
SPARC Enterprise M5000
SPARC Enterprise M3000
SPARC Enterprise M4000
FlashSystem 900 9840-AE2 and 9843-AE2
Oracle Communications Policy Management
TransactionVision
WebSphere Message Broker Toolkit
Business Process Insight
Real User Monitor
XIV Management Tools
Product and Portfolio Manager
Business Process Monitor
Virtualization Performance Viewer
UCMDB Browser
Reporter
OnCommand Unified Manager for DataONTAP
Integration Adaptor
HP Release Control
BSM Connector
Discovery and Dependency Mapping Inventory (DDMI)
Connect-IT
UCMDB
UCMDB Configuration Manager
Universal Discovery
Operations Agent Virtual Appliance
FlashSystem 840 9840-AE1 & 9843-AE1
HP-UX Web Server Suite
WebSphere Message Broker
Clustered Data ONTAP
Integration Toolkit
XIV Storage System Gen2
P6000 Command View Software
TS2900 Tape Autoloader
HPE Service Manager
HP Performance Manager
HP Operations Manager
HP Operations Manager for Unix
HP Operations Manager for Linux
HP AssetManager
IBM Integration Bus
OnCommand Unified Manager Core Package
vBulletin
Microsoft Exchange Server
IBM i
Data ONTAP operating in 7-Mode

How to mitigate CVE-2015-2808

Update the versions 9.30, 9.31, 9.32, 9.33, 9.34 at: http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05193347

HP Release Control - update to 9.21 P3
FlashSystem 900 9840-AE2 and 9843-AE2 - update to 1.3.0.2
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.3.0.2
HP-UX Web Server Suite - update to 2.2.29.02
WebSphere Message Broker - addressed in versions 7.0.0.8, 8.0.0.7
Data ONTAP operating in 7-Mode - update to 8.3
Clustered Data ONTAP - update to 8.3
Integration Toolkit - update to 9.0 Fix Pack 3
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
TS2900 Tape Autoloader - update to 0037

External References

Related Security Bulletins