CVE-2014-0852
Published Aug 16, 2014
Last updated 7 years ago
Overview
- Description
- IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "497AD737-872C-4B7A-9164-09C05087E5B9", "versionEndIncluding": "4.0.2.15" }, { "criteria": "cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C54FA460-80B9-4B70-98A0-073CE5457A44" }, { "criteria": "cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:6.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C76A74C5-B766-402F-B59A-A9AF7F2C17D2" }, { "criteria": "cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:6.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92B4CB34-9F2F-4F3A-974D-476EB02314B7" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ibm:websphere_datapower_soa_appliance:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB1E9FF7-1875-4F97-9AA5-E4A7DBE991DD" } ], "operator": "OR" } ], "operator": "AND" } ]