CVE-2015-3197
MEDIUMOpenSSL <1.0.1r-1.0.2f - Info Disclosure
Title source: llmDescription
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
Exploits (1)
References (36)
... and 16 more
Scores
CVSS v3
5.9
EPSS
0.2195
EPSS Percentile
95.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-310
CWE-200
Status
draft
Affected Products (38)
oracle/tuxedo
oracle/exalogic_infrastructure
oracle/exalogic_infrastructure
oracle/peoplesoft_enterprise_peopletools
oracle/peoplesoft_enterprise_peopletools
oracle/peoplesoft_enterprise_peopletools
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
openssl/openssl
... and 23 more
Timeline
Published
Feb 15, 2016
Tracked Since
Feb 18, 2026