Skip to main content

IBM WebSphere Application Server SSL/TLS RC4 Vulnerability

Last Update Date: 15 Apr 2015 11:43 Release Date: 15 Apr 2015 3370 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

The RC4 algorithm, as used in the TLS protocol and SSL protocol, could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability to remotely expose account credentials without requiring an active man-in-the-middle session.


Impact

  • Information Disclosure

System / Technologies affected

  • 6.1, 7.0, 8.0, 8.5, 8.5.5

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link