CVE-2015-2802

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.
References
Link Resource
http://marc.info/?l=bugtraq&m=143455780010289&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=143629738517220&w=2 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/75258 Third Party Advisory VDB Entry
https://packetstormsecurity.com/files/cve/CVE-2015-2802 Third Party Advisory VDB Entry
https://securitytracker.com/id/1032599 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:asset_manager:9.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.31:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.32:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager_cloudsystem_chargeback:9.40:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:hp:sitescope:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.30:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

09 Sep 2021, 12:53

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:solaris:-:*:*:*:*:*:*:* cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Information

Published : 2020-02-04 21:15

Updated : 2023-12-10 13:13


NVD link : CVE-2015-2802

Mitre link : CVE-2015-2802

CVE.ORG link : CVE-2015-2802


JSON object : View

Products Affected

hp

  • asset_manager
  • asset_manager_cloudsystem_chargeback
  • sitescope

microsoft

  • windows

oracle

  • solaris

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor