CVE-2015-2808

low
Published 2015-04-01 · Modified 2026-05-28
CVSS v3
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2
5.0
VIR risk
3.7

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Predictions

Exploit likelihood
47%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-2808

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-2808.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian7.0affected
debian debian8.0affected
redhat rhel5.0affected
redhat rhel6.0affected
redhat rhel7.0affected
redhat rhel6.6affected
redhat rhel7.1affected
redhat rhel7.2affected
redhat rhel7.3affected
redhat rhel7.4affected
suse suse13.1affected
suse suse13.2affected
suse suse11affected
suse suse12affected
suse suse10affected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
redhat rhel7.5affected
redhat rhel7.6affected
redhat rhel7.7affected
debian debiansidfixed8u66-b01-1

Application impact

VendorProductVersionsFixed
oraclecommunications_application_session_controller{"startIncluding":"3.0.0","endIncluding":"3.9.0"}
oraclecommunications_policy_management{"endExcluding":"9.9.2"}9.9.2
oraclehttp_server11.1.1.7.0
oraclehttp_server11.1.1.9.0
oraclehttp_server12.1.3.0.0
oraclehttp_server12.2.1.1.0
oraclehttp_server12.2.1.2.0
redhatsatellite5.7
suselinux_enterprise_debuginfo11
susemanager1.7
redhatsatellite5.6
huaweioceanstor_replicationdirectorv100r003c00
huaweipolicy_centerv100r003c00
huaweipolicy_centerv100r003c10
huaweismc2.0v100r002c01
huaweismc2.0v100r002c02
huaweismc2.0v100r002c03
huaweismc2.0v100r002c04
huaweiultravrv100r003c00
ibmcognos_metrics_manager10.1
ibmcognos_metrics_manager10.1.1
ibmcognos_metrics_manager10.2
ibmcognos_metrics_manager10.2.1
ibmcognos_metrics_manager10.2.2
fujitsusparc_enterprise_m3000-
fujitsusparc_enterprise_m4000-
fujitsusparc_enterprise_m5000-
fujitsusparc_enterprise_m8000-
fujitsusparc_enterprise_m9000-
huaweie6000-
huaweie9000-
huaweioceanstor_18500-
huaweioceanstor_18800-
huaweioceanstor_18800f-
huaweioceanstor_9000-
huaweioceanstor_cse-
huaweioceanstor_hvs85t-
huaweioceanstor_s2600t-
huaweioceanstor_s5500t-
huaweioceanstor_s5600t-
huaweioceanstor_s5800t-
huaweioceanstor_s6800t-
huaweioceanstor_vis6600t-
huaweiquidway_s9300-
huaweis7700-
huawei9700-
huaweis12700-
huaweis2700-
huaweis3700-
huaweis5700ei-
huaweis5700hi-
huaweis5700si-
huaweis5710ei-
huaweis5710hi-
huaweis6700-
huaweis2750-
huaweis5700li-
huaweis5700s-li-
huaweis5720hi-
huaweis5720ei-
huaweite60-

References

CWEs

CWE-327

Verify integrity in audit chain (admin only). AS-IS.