CVE-2015-2808
published 2015-04-01CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which…
PriorityP335low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
73.85%
99.4th percentile
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u66-b01-1 (sid) | openjdk-8 8u66-b01-1 (sid) |
| fujitsu | sparc_enterprise_m3000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m4000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m5000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m8000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m9000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| huawei | oceanstor_replicationdirector | — | — |
| huawei | policy_center | — | — |
| huawei | policy_center | — | — |
| huawei | smc2.0 | — | — |
| huawei | smc2.0 | — | — |
| huawei | smc2.0 | — | — |
| huawei | smc2.0 | — | — |
| huawei | ultravr | — | — |
| ibm | cognos_metrics_manager | — | — |
| ibm | cognos_metrics_manager | — | — |
| ibm | cognos_metrics_manager | — | — |
| ibm | cognos_metrics_manager | — | — |
| ibm | cognos_metrics_manager | — | — |
| opensuse | opensuse | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect RC4 cipher suite usage in TLS/SSL traffic; presence of RC4-based cipher suites in ClientHello or ServerHello indicates exposure to the Bar Mitzvah attack (CVE-2015-2808) ↗
- →Monitor for RC4 cipher suite negotiation in TLS handshakes; the attack targets the initial bytes of the RC4 keystream via the Invariance Weakness (L-shape key pattern) which preserves part of the state permutation intact throughout the initialization process, leaking LSBs of the output stream ↗
- →Check jdk.tls.disabledAlgorithms security property in java.security; if RC4 is absent from this list, the JVM is potentially vulnerable to CVE-2015-2808 ↗
- ·This vulnerability is a design flaw in the RC4 algorithm itself, not an implementation bug; patching involves disabling RC4 cipher suites rather than fixing RC4 code ↗
- ·IBM JDK fix disables all RC4 SSL/TLS cipher suites by default; IBM Java 7+ adds RC4 to jdk.tls.disabledAlgorithms, but IBM Java 5.0 and 6 do not support algorithm-level disabling via that property ↗
- ·Oracle JDK (7u85, 8u51) removes RC4 from default enabled cipher suites but does NOT add it to jdk.tls.disabledAlgorithms, meaning RC4 can still be re-enabled via setEnabledCipherSuites(); a new jdk.tls.legacyAlgorithms property was introduced to deprioritize RC4 on the server side ↗
- ·Mitsubishi Electric air conditioning systems (G-150AD, AG-150A-A/J, GB-50AD, GB-50ADA-A/J, EB-50GU-A/J, AE-200/50/EW-50 series, TE/TW-50A) are affected by CVE-2015-2808 in their TLS implementation; no known public exploits but attack complexity is high ↗
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle HTTP Server up to 12.2.1.2.0 Web Listener cryptographic issue (Nessus ID 83135 / ID 91499)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-2808 [LOW] Oracle HTTP Server up to 12.2.1.2.0 Web Listener cryptographic issue (Nessus ID 83135 / ID 91499)
A vulnerability labeled as problematic has been found in Oracle HTTP Server 11.1.1.7.0/11.1.1.9.0/12.1.3.0.0/12.2.1.1.0/12.2.1.2.0. This issue affects some unknown processing of the component Web Listener. The manipulation results in cryptographic issues.
This vulnerability is known as CVE-2015-2808. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Communications Policy Management up to 9.9.1 Security cryptographic issue (Nessus ID 83135 / ID 91499)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-2808 [LOW] Oracle Communications Policy Management up to 9.9.1 Security cryptographic issue (Nessus ID 83135 / ID 91499)
A vulnerability classified as problematic was found in Oracle Communications Policy Management up to 9.9.1. This issue affects some unknown processing of the component Security. The manipulation results in cryptographic issues.
This vulnerability is identified as CVE-2015-2808. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
VulDB
Oracle SPARC Enterprise M Server cryptographic issue (Nessus ID 83135 / ID 91499)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-2808 [LOW] Oracle SPARC Enterprise M Server cryptographic issue (Nessus ID 83135 / ID 91499)
A vulnerability, which was classified as critical, was found in Oracle SPARC Enterprise M Server. Impacted is an unknown function. Executing a manipulation can lead to cryptographic issues.
This vulnerability is handled as CVE-2015-2808. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
VulDB
TLS Protocol/SSL Protocol RC4 Encryption Bar Mitzvah Attack cryptographic issue (Nessus ID 83135 / ID 91499)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-2808 [LOW] TLS Protocol/SSL Protocol RC4 Encryption Bar Mitzvah Attack cryptographic issue (Nessus ID 83135 / ID 91499)
A vulnerability, which was classified as problematic, was found in TLS Protocol and SSL Protocol. This vulnerability affects unknown code of the component RC4 Encryption. Such manipulation leads to cryptographic issues (Bar Mitzvah Attack).
This vulnerability is uniquely identified as CVE-2015-2808. The attack can be launched remotely. No exploit exists.
GHSA
GHSA-jcj6-c96p-jcmm: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, w
ghsa_unreviewed·2022-05-13
CVE-2015-2808 [MEDIUM] CWE-327 GHSA-jcj6-c96p-jcmm: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, w
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
OSV
openjdk-7 vulnerabilities
osv·2015-07-30·CVSS 9.8
CVE-2015-2590 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this update modifies OpenJDK behavior to
reject
OSV
CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, w
osv·2015-03-31·CVSS 5.0
CVE-2015-2808 [MEDIUM] CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, w
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
CISA ICS
Mitsubishi Electric Air Conditioning Systems
cisa_ics·2022-06-20
Mitsubishi Electric Air Conditioning Systems
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric Air Conditioning Systems
Last RevisedJune 20, 2022
Alert CodeICSA-22-160-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely
- Vendor: Mitsubishi Electric
- Equipment: Air Conditioning Systems
- Vulnerabilities: Use of a Broken or Risky Cryptographic Algorithm, Exposure of Sensitive Information to an Unauthorized Actor, Channel Accessible by Non-Endpoint
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose or tamper data in communication between the air conditioning system and
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 9.8
CVE-2015-2590 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2808 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2613 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this
Red Hat
SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
vendor_redhat·2015-03-30·CVSS 5.0
CVE-2015-2808 [MEDIUM] SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Statement: This flaw is related to the design of the RC4 protocol and not its implementation. Therefore there are no plans to correct this issue in Red Hat Enterprise Linux 5, 6 and 7. Future updates may disable the use of RC4 in various components.
Package: gnutls (Red Hat E
Debian
CVE-2015-2808: openjdk-8 - The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not proper...
vendor_debian·2015·CVSS 5.0
CVE-2015-2808 [MEDIUM] CVE-2015-2808: openjdk-8 - The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not proper...
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Scope: local
sid: resolved (fixed in 8u66-b01-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2808 SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
bugzilla·2015-03-30·CVSS 5.0
CVE-2015-2808 [MEDIUM] CVE-2015-2808 SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
CVE-2015-2808 SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
It was discovered that the Invariance Weakness of the RC4 stream cipher could be used to recover plaintext from a TLS connection, when RC4 encryption is used.
"The Invariance Weakness is an L-shape key pattern in RC4 keys, which once it exists in an RC4 key, preserves part of the state permutation intact throughout the initialization process. This intact part includes the least significant bits of the permutation, when processed by the PRGA algorithm, determines the least significant bits of the allegedly pseudo-random output stream along a long prefix of the stream."
This can lead to significant leakage of plaintext bytes from the ciphertext.
External Reference:
http://www.imperva.com/docs/HII_Attacking_S
Bugzilla
use the default min/max TLS version provided by NSS [RHEL-7]
bugzilla·2014-12-03
[CRITICAL] use the default min/max TLS version provided by NSS [RHEL-7]
use the default min/max TLS version provided by NSS [RHEL-7]
Description of problem:
Curl does not negotiate an SSL/TLS connections from strongest down to weakest as presented by the server.
Version-Release number of selected component (if applicable):
RHEL 7
curl 7.29.0 (x86_64-redhat-linux-gnu) libcurl/7.29.0 NSS/3.15.4 zlib/1.2.7 libidn/1.28 libssh2/1.4.3
How reproducible: Very
Steps to Reproduce:
1. Install httpd
2. setup SSL and define the following:
SSLProtocol TLSv1 TLSv1.1 TLSv1.2
SSLCipherSuite HIGH
3. curl -IL https://$(hostname) -v
Actual results:
* About to connect() to $(hostname) port 443 (#0)
* Trying XXX.XXX.XXX.XXX...
* Connected to $(hostname) (10.13.213.65) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* CAfile: /etc/pki/tls/certs/cacert.crt
C
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://marc.info/?l=bugtraq&m=143456209711959&w=2http://marc.info/?l=bugtraq&m=143629696317098&w=2http://marc.info/?l=bugtraq&m=143741441012338&w=2http://marc.info/?l=bugtraq&m=143817021313142&w=2http://marc.info/?l=bugtraq&m=143817899717054&w=2http://marc.info/?l=bugtraq&m=143818140118771&w=2http://marc.info/?l=bugtraq&m=144043644216842&w=2http://marc.info/?l=bugtraq&m=144059660127919&w=2http://marc.info/?l=bugtraq&m=144059703728085&w=2http://marc.info/?l=bugtraq&m=144060576831314&w=2http://marc.info/?l=bugtraq&m=144060606031437&w=2http://marc.info/?l=bugtraq&m=144069189622016&w=2http://marc.info/?l=bugtraq&m=144102017024820&w=2http://marc.info/?l=bugtraq&m=144104533800819&w=2http://marc.info/?l=bugtraq&m=144104565600964&w=2http://marc.info/?l=bugtraq&m=144493176821532&w=2http://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV71888http://www-01.ibm.com/support/docview.wss?uid=swg1IV71892http://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www-304.ibm.com/support/docview.wss?uid=swg21903565http://www-304.ibm.com/support/docview.wss?uid=swg21960015http://www-304.ibm.com/support/docview.wss?uid=swg21960769http://www.debian.org/security/2015/dsa-3316http://www.debian.org/security/2015/dsa-3339http://www.huawei.com/en/psirt/security-advisories/hw-454055http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/73684http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1032599http://www.securitytracker.com/id/1032600http://www.securitytracker.com/id/1032707http://www.securitytracker.com/id/1032708http://www.securitytracker.com/id/1032734http://www.securitytracker.com/id/1032788http://www.securitytracker.com/id/1032858http://www.securitytracker.com/id/1032868http://www.securitytracker.com/id/1032910http://www.securitytracker.com/id/1032990http://www.securitytracker.com/id/1033071http://www.securitytracker.com/id/1033072http://www.securitytracker.com/id/1033386http://www.securitytracker.com/id/1033415http://www.securitytracker.com/id/1033431http://www.securitytracker.com/id/1033432http://www.securitytracker.com/id/1033737http://www.securitytracker.com/id/1033769http://www.securitytracker.com/id/1036222http://www.ubuntu.com/usn/USN-2696-1http://www.ubuntu.com/usn/USN-2706-1http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htmhttps://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04687922https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888https://kb.juniper.net/JSA10783https://kc.mcafee.com/corporate/index?page=content&id=SB10163https://security.gentoo.org/glsa/201512-10https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf
+ 102 more references
2015-04-01
Published