CVE Vulnerabilities

CVE-2014-0852

Published: Aug 16, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.

Affected Software

NameVendorStart VersionEnd Version
Websphere_datapower_soa_appliance_firmwareIbm*4.0.2.15 (including)
Websphere_datapower_soa_appliance_firmwareIbm5.0.0 (including)5.0.0 (including)
Websphere_datapower_soa_appliance_firmwareIbm6.0.0 (including)6.0.0 (including)
Websphere_datapower_soa_appliance_firmwareIbm6.0.1 (including)6.0.1 (including)

References