CVE-2015-2808: Low severity Oracle Communications Application Session Controller vulnerability

Published Mar 30, 2015
·
Updated

It was discovered that the Invariance Weakness of the RC4 stream cipher could be used to recover plaintext from a TLS connection, when RC4 encryption is used.

"The Invariance Weakness is an L-shape key pattern in RC4 keys, which once it exists in an RC4 key, preserves part of the state permutation intact throughout the initialization process. This intact part includes the least significant bits of the permutation, when processed by the PRGA algorithm, determines the least significant bits of the allegedly pseudo-random output stream along a long prefix of the stream."

This can lead to significant leakage of plaintext bytes from the ciphertext.

External Reference:

http://www.imperva.com/docs/HIIAttackingSSLwhenusingRC4.pdf

Other sources

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Affected Software

249 affected componentsFixes available
redhat/java<1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11
1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11
redhat/java<1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11
1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11
redhat/java<1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6
1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6
redhat/java<1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6
1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6
redhat/java<1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6
1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6
redhat/java<1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1
1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1
redhat/java<1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1
1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1
redhat/java<1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1
1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1
redhat/java<1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11
1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11
redhat/java<1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11
1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11
redhat/java<1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
redhat/java<1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5
1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5
redhat/java<1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5
1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5
redhat/java<1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6
1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6
redhat/java<1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6
1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6
redhat/java<1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7
1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7
redhat/java<1.8.0-openjdk-1:1.8.0.51-1.b16.el7_1
1.8.0-openjdk-1:1.8.0.51-1.b16.el7_1
redhat/java<1.7.0-openjdk-1:1.7.0.85-2.6.1.2.el7_1
1.7.0-openjdk-1:1.7.0.85-2.6.1.2.el7_1
redhat/java<1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1
1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1
redhat/java<1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
redhat/java<1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6
1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6
redhat/java<1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6
1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6
redhat/java<1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el7_1
1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el7_1
debian/openjdk-8
8u442-ga-2
Oracle Communications Application Session Controller>=3.0.0<=3.9.0
Oracle Communications Policy Management<9.9.2
Oracle HTTP Server=11.1.1.7.0
Oracle HTTP Server=11.1.1.9.0
Oracle HTTP Server=12.1.3.0.0
Oracle HTTP Server=12.2.1.1.0
Oracle HTTP Server=12.2.1.2.0
Oracle Integrated Lights Out Manager Firmware>=3.0.0<=3.2.11
Oracle Integrated Lights Out Manager Firmware>=4.0.0<=4.0.4
Debian Debian Linux=7.0
Debian Debian Linux=8.0
redhat Satellite=5.7
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=6.6
redhat Enterprise Linux Eus=7.1
redhat Enterprise Linux Eus=7.2
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=6.6
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
SUSE Linux Enterprise Debuginfo=11-sp3
SUSE Linux Enterprise Debuginfo=11-sp4
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=11-sp3
SUSE Linux Enterprise Desktop=11-sp4
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=10-sp4
SUSE Linux Enterprise Server=11-sp1
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server Vmware=11-sp3
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Software Development Kit=11-sp3
SUSE Linux Enterprise Software Development Kit=12
SUSE Manager=1.7
SUSE Linux Enterprise Server=11-sp2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
redhat Satellite=5.6
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
Fujitsu Sparc Enterprise M3000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M3000
Fujitsu Sparc Enterprise M4000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M4000
Fujitsu Sparc Enterprise M5000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M5000
Fujitsu Sparc Enterprise M8000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M8000
Fujitsu Sparc Enterprise M9000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M9000
Huawei E6000 Firmware
Huawei E6000
Huawei E9000 Firmware
Huawei E9000
Huawei Oceanstor 18500 Firmware
Huawei Oceanstor 18500
Huawei Oceanstor 18800 Firmware
Huawei Oceanstor 18800
Huawei Oceanstor 18800f Firmware
Huawei Oceanstor 18800f
Huawei Oceanstor 9000 Firmware
Huawei Oceanstor 9000
Huawei Oceanstor Cse Firmware
Huawei Oceanstor Cse
Huawei Oceanstor Hvs85t Firmware
Huawei Oceanstor Hvs85t
Huawei Oceanstor S2600t Firmware
Huawei Oceanstor S2600t
Huawei Oceanstor S5500t Firmware
Huawei Oceanstor S5500t
Huawei Oceanstor S5600t Firmware
Huawei Oceanstor S5600t
Huawei Oceanstor S5800t Firmware
Huawei Oceanstor S5800t
Huawei Oceanstor S6800t Firmware
Huawei Oceanstor S6800t
Huawei Oceanstor Vis6600t Firmware
Huawei Oceanstor Vis6600t
Huawei Quidway S9300 Firmware
Huawei Quidway S9300
Huawei S7700 Firmware
Huawei S7700
Huawei 9700 Firmware
Huawei 9700
Huawei S12700 Firmware
Huawei S12700
Huawei S2700 Firmware
Huawei S2700
Huawei S3700 Firmware
Huawei S3700
Huawei S5700ei Firmware
Huawei S5700ei
Huawei S5700hi Firmware
Huawei S5700hi
Huawei S5700si Firmware
Huawei S5700si
Huawei S5710ei Firmware
Huawei S5710ei
Huawei S5710hi Firmware
Huawei S5710hi
Huawei S6700 Firmware
Huawei S6700
Huawei S2750 Firmware
Huawei S2750
Huawei S5700li Firmware
Huawei S5700li
Huawei S5700s-li Firmware
Huawei S5700s-li
Huawei S5720hi Firmware
Huawei S5720HI
Huawei S5720ei Firmware
Huawei S5720EI
Huawei Te60 Firmware
Huawei TE60
Huawei Oceanstor Replicationdirector=v100r003c00
Huawei Policy Center=v100r003c00
Huawei Policy Center=v100r003c10
Huawei SMC2.0=v100r002c01
Huawei SMC2.0=v100r002c02
Huawei SMC2.0=v100r002c03
Huawei SMC2.0=v100r002c04
Huawei Ultravr=v100r003c00
IBM Cognos Metrics Manager=10.1
IBM Cognos Metrics Manager=10.1.1
IBM Cognos Metrics Manager=10.2
IBM Cognos Metrics Manager=10.2.1
IBM Cognos Metrics Manager=10.2.2
All of the following
SUSE Manager=1.7
SUSE Linux Enterprise Server=11-sp2
All of the following
redhat Satellite=5.6
Any of the following
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
All of the following
Fujitsu Sparc Enterprise M3000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M3000
All of the following
Fujitsu Sparc Enterprise M4000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M4000
All of the following
Fujitsu Sparc Enterprise M5000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M5000
All of the following
Fujitsu Sparc Enterprise M8000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M8000
All of the following
Fujitsu Sparc Enterprise M9000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M9000
All of the following
Huawei E6000 Firmware
Huawei E6000
All of the following
Huawei E9000 Firmware
Huawei E9000
All of the following
Huawei Oceanstor 18500 Firmware
Huawei Oceanstor 18500
All of the following
Huawei Oceanstor 18800 Firmware
Huawei Oceanstor 18800
All of the following
Huawei Oceanstor 18800f Firmware
Huawei Oceanstor 18800f
All of the following
Huawei Oceanstor 9000 Firmware
Huawei Oceanstor 9000
All of the following
Huawei Oceanstor Cse Firmware
Huawei Oceanstor Cse
All of the following
Huawei Oceanstor Hvs85t Firmware
Huawei Oceanstor Hvs85t
All of the following
Huawei Oceanstor S2600t Firmware
Huawei Oceanstor S2600t
All of the following
Huawei Oceanstor S5500t Firmware
Huawei Oceanstor S5500t
All of the following
Huawei Oceanstor S5600t Firmware
Huawei Oceanstor S5600t
All of the following
Huawei Oceanstor S5800t Firmware
Huawei Oceanstor S5800t
All of the following
Huawei Oceanstor S6800t Firmware
Huawei Oceanstor S6800t
All of the following
Huawei Oceanstor Vis6600t Firmware
Huawei Oceanstor Vis6600t
All of the following
Huawei Quidway S9300 Firmware
Huawei Quidway S9300
All of the following
Huawei S7700 Firmware
Huawei S7700
All of the following
Huawei 9700 Firmware
Huawei 9700
All of the following
Huawei S12700 Firmware
Huawei S12700
All of the following
Huawei S2700 Firmware
Huawei S2700
All of the following
Huawei S3700 Firmware
Huawei S3700
All of the following
Huawei S5700ei Firmware
Huawei S5700ei
All of the following
Huawei S5700hi Firmware
Huawei S5700hi
All of the following
Huawei S5700si Firmware
Huawei S5700si
All of the following
Huawei S5710ei Firmware
Huawei S5710ei
All of the following
Huawei S5710hi Firmware
Huawei S5710hi
All of the following
Huawei S6700 Firmware
Huawei S6700
All of the following
Huawei S2750 Firmware
Huawei S2750
All of the following
Huawei S5700li Firmware
Huawei S5700li
All of the following
Huawei S5700s-li Firmware
Huawei S5700s-li
All of the following
Huawei S5720hi Firmware
Huawei S5720HI
All of the following
Huawei S5720ei Firmware
Huawei S5720EI
All of the following
Huawei Te60 Firmware
Huawei TE60

Event History

Mar 30, 2015
CVE Published
12:00 AM
Data Sourced
via Red Hat·08:56 AM
DescriptionSeverityAffected Software
Apr 1, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:09 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:08 AM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-2808?

The severity of CVE-2015-2808 is classified as high due to its potential to expose sensitive information by exploiting the RC4 stream cipher's weaknesses.

2

How do I fix CVE-2015-2808?

To fix CVE-2015-2808, it is recommended to upgrade to a version of Java that does not use the RC4 cipher for TLS connections.

3

Which Java versions are affected by CVE-2015-2808?

CVE-2015-2808 affects multiple Java versions including 1.5, 1.6, 1.7, and 1.8, particularly those using RC4 in their cipher suites.

4

What impact does CVE-2015-2808 have on TLS connections?

CVE-2015-2808 can lead to the recovery of plaintext from TLS connections when vulnerable RC4 encryption is used, compromising data security.

5

Is there a workaround for CVE-2015-2808?

A temporary workaround for CVE-2015-2808 is to disable RC4 encryption in your applications to mitigate the risk until an upgrade can be performed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203