CVE-2015-2802

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.
References
Link Resource
http://www.securityfocus.com/bid/75258 Third Party Advisory VDB Entry
http://marc.info/?l=bugtraq&m=143629738517220&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=143455780010289&w=2 Mailing List Third Party Advisory
https://securitytracker.com/id/1032599 Third Party Advisory VDB Entry
https://packetstormsecurity.com/files/cve/CVE-2015-2802 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:asset_manager:9.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.31:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.32:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager_cloudsystem_chargeback:9.40:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:hp:sitescope:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.30:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Information

Published : 2020-02-04 13:15

Updated : 2021-09-09 05:53


NVD link : CVE-2015-2802

Mitre link : CVE-2015-2802


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

hp

  • asset_manager
  • sitescope
  • asset_manager_cloudsystem_chargeback

microsoft

  • windows

linux

  • linux_kernel

oracle

  • solaris