CVE-2015-2802
Summary
| CVE | CVE-2015-2802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 21:15:00 UTC |
| Updated | 2021-09-09 12:53:00 UTC |
| Description | An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Asset Manager | 9.30 | All | All | All |
| Application | Hp | Asset Manager | 9.31 | All | All | All |
| Application | Hp | Asset Manager | 9.32 | All | All | All |
| Application | Hp | Asset Manager | 9.40 | All | All | All |
| Application | Hp | Asset Manager | 9.41 | All | All | All |
| Application | Hp | Asset Manager | 9.50 | All | All | All |
| Application | Hp | Asset Manager | 9.30 | All | All | All |
| Application | Hp | Asset Manager | 9.31 | All | All | All |
| Application | Hp | Asset Manager | 9.32 | All | All | All |
| Application | Hp | Asset Manager | 9.40 | All | All | All |
| Application | Hp | Asset Manager | 9.41 | All | All | All |
| Application | Hp | Asset Manager | 9.50 | All | All | All |
| Application | Hp | Asset Manager Cloudsystem Chargeback | 9.40 | All | All | All |
| Application | Hp | Asset Manager Cloudsystem Chargeback | 9.40 | All | All | All |
| Application | Hp | Sitescope | 11.30 | All | All | All |
| Application | Hp | Sitescope | 11.30 | All | All | All |
| Application | Hp | Sitescope | All | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Oracle | Solaris | - | All | All | All |
| Operating System | Oracle | Solaris | - | All | All | All |
| Application | Oracle | Solaris | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2015-2802 ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| '[security bulletin] HPSBGN03352 rev.2 - HP Asset Manager Using RC4, Remote Disclosure of Information' - MARC | CONFIRM | marc.info | Mailing List, Third Party Advisory |
| HP SiteScope TLS RC4 Algorithm Lets Remote Users Decrypt Data - SecurityTracker | MISC | securitytracker.com | Third Party Advisory, VDB Entry |
| HP SiteScope Remote Unspecified Information Disclosure Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| '[security bulletin] HPSBGN03350 rev.1 - HP SiteScope Using RC4, Remote Disclosure of Information' - MARC | CONFIRM | marc.info | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.