Information disclosure in Hewlett Packard Enterprise Development LP products - CVE-2015-2808
Published: July 5, 2016 / Updated: November 22, 2018
Vulnerability identifier: #VU90
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2808
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information communicated by target system.
The vulnerability exists due to access control error. A remote unauthenticated attacker can obtain RC4 encrypted data and conduct a brute-force key guessing attack by monitoring TLS network traffic.
Successful exploitation of this vulnerability may result in disclosure of system information.
The vulnerability exists due to access control error. A remote unauthenticated attacker can obtain RC4 encrypted data and conduct a brute-force key guessing attack by monitoring TLS network traffic.
Successful exploitation of this vulnerability may result in disclosure of system information.
Affected software
SPARC Enterprise M9000
SPARC Enterprise M8000
SPARC Enterprise M5000
SPARC Enterprise M3000
SPARC Enterprise M4000
FlashSystem 900 9840-AE2 and 9843-AE2
Oracle Communications Policy Management
TransactionVision
WebSphere Message Broker Toolkit
Business Process Insight
Real User Monitor
XIV Management Tools
Product and Portfolio Manager
Business Process Monitor
Virtualization Performance Viewer
UCMDB Browser
Reporter
OnCommand Unified Manager for DataONTAP
Integration Adaptor
HP Release Control
BSM Connector
Discovery and Dependency Mapping Inventory (DDMI)
Connect-IT
UCMDB
UCMDB Configuration Manager
Universal Discovery
Operations Agent Virtual Appliance
FlashSystem 840 9840-AE1 & 9843-AE1
HP-UX Web Server Suite
WebSphere Message Broker
Clustered Data ONTAP
Integration Toolkit
XIV Storage System Gen2
P6000 Command View Software
TS2900 Tape Autoloader
HPE Service Manager
HP Performance Manager
HP Operations Manager
HP Operations Manager for Unix
HP Operations Manager for Linux
HP AssetManager
IBM Integration Bus
OnCommand Unified Manager Core Package
vBulletin
Microsoft Exchange Server
IBM i
Data ONTAP operating in 7-Mode
SPARC Enterprise M8000
SPARC Enterprise M5000
SPARC Enterprise M3000
SPARC Enterprise M4000
FlashSystem 900 9840-AE2 and 9843-AE2
Oracle Communications Policy Management
TransactionVision
WebSphere Message Broker Toolkit
Business Process Insight
Real User Monitor
XIV Management Tools
Product and Portfolio Manager
Business Process Monitor
Virtualization Performance Viewer
UCMDB Browser
Reporter
OnCommand Unified Manager for DataONTAP
Integration Adaptor
HP Release Control
BSM Connector
Discovery and Dependency Mapping Inventory (DDMI)
Connect-IT
UCMDB
UCMDB Configuration Manager
Universal Discovery
Operations Agent Virtual Appliance
FlashSystem 840 9840-AE1 & 9843-AE1
HP-UX Web Server Suite
WebSphere Message Broker
Clustered Data ONTAP
Integration Toolkit
XIV Storage System Gen2
P6000 Command View Software
TS2900 Tape Autoloader
HPE Service Manager
HP Performance Manager
HP Operations Manager
HP Operations Manager for Unix
HP Operations Manager for Linux
HP AssetManager
IBM Integration Bus
OnCommand Unified Manager Core Package
vBulletin
Microsoft Exchange Server
IBM i
Data ONTAP operating in 7-Mode
How to mitigate CVE-2015-2808
Update the versions 9.30, 9.31, 9.32, 9.33, 9.34 at: http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05193347
HP Release Control - update to 9.21 P3
FlashSystem 900 9840-AE2 and 9843-AE2 - update to 1.3.0.2
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.3.0.2
HP-UX Web Server Suite - update to 2.2.29.02
WebSphere Message Broker - addressed in versions 7.0.0.8, 8.0.0.7
Data ONTAP operating in 7-Mode - update to 8.3
Clustered Data ONTAP - update to 8.3
Integration Toolkit - update to 9.0 Fix Pack 3
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
TS2900 Tape Autoloader - update to 0037
FlashSystem 900 9840-AE2 and 9843-AE2 - update to 1.3.0.2
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.3.0.2
HP-UX Web Server Suite - update to 2.2.29.02
WebSphere Message Broker - addressed in versions 7.0.0.8, 8.0.0.7
Data ONTAP operating in 7-Mode - update to 8.3
Clustered Data ONTAP - update to 8.3
Integration Toolkit - update to 9.0 Fix Pack 3
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
TS2900 Tape Autoloader - update to 0037
External References
Related Security Bulletins
- Information disclosure in HPE Service Manager
- Information disclosure in HPE Service Manager
- Multiple vulnerabilities in IBM WebSphere Message Broker and IBM Integration Bus
- Information disclosure in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in HP Operations Manager for Windows
- Information disclosure in HP Virtualization Performance Viewer
- Information disclosure in HP Operations Manager i
- Information disclosure in HP Reporter
- Information disclosure in HP Operations Agent
- Multiple vulnerabilities in HP Performance Manager
- Multiple vulnerabilities in HP Integration Adaptor
- Multiple vulnerabilities in HP BSM Connector (BSMC)
- Information disclosure in HP TransactionVision
- Information disclosure in HP Business Process Insight
- Information disclosure in HP Real User Monitor
- Information disclosure in HP Asset Manager
- Information disclosure in HP Project and Portfolio Management Center
- Information disclosure in HP Business Process Monitor
- Information disclosure in HP Connect-IT Using RC4
- Information disclosure in HP UCMDB, Configuration Manager, UCMDB Browser, and Universal Discovery
- Information disclosure in HP Discovery and Dependency Mapping Inventory (DDMI)
- Information disclosure in HP Release Control
- Multiple vulnerabilities in HP Operations Manager for UNIX and Linux
- Multiple vulnerabilities in HP P6000 Command View Software
- Multiple vulnerabilities in HP-UX Web Server Suite
- Information disclosure in Multiple N-series Products
- Information disclosure in IBM TS2900
- Information disclosure in IBM XIV Management Tools
- Information disclosure in IBM XIV Storage System Gen2
- IBM i update for RC4 algorithm