CVE-2015-2802

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.
References
Link Resource
http://marc.info/?l=bugtraq&m=143455780010289&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=143629738517220&w=2 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/75258 Third Party Advisory VDB Entry
https://packetstormsecurity.com/files/cve/CVE-2015-2802 Third Party Advisory VDB Entry
https://securitytracker.com/id/1032599 Third Party Advisory VDB Entry
http://marc.info/?l=bugtraq&m=143455780010289&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=143629738517220&w=2 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/75258 Third Party Advisory VDB Entry
https://packetstormsecurity.com/files/cve/CVE-2015-2802 Third Party Advisory VDB Entry
https://securitytracker.com/id/1032599 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:asset_manager:9.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.31:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.32:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager:9.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:asset_manager_cloudsystem_chargeback:9.40:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:hp:sitescope:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.30:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:28

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=143455780010289&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=143455780010289&w=2 - Mailing List, Third Party Advisory
References () http://marc.info/?l=bugtraq&m=143629738517220&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=143629738517220&w=2 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/75258 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/75258 - Third Party Advisory, VDB Entry
References () https://packetstormsecurity.com/files/cve/CVE-2015-2802 - Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/cve/CVE-2015-2802 - Third Party Advisory, VDB Entry
References () https://securitytracker.com/id/1032599 - Third Party Advisory, VDB Entry () https://securitytracker.com/id/1032599 - Third Party Advisory, VDB Entry

Information

Published : 2020-02-04 21:15

Updated : 2024-11-21 02:28


NVD link : CVE-2015-2802

Mitre link : CVE-2015-2802

CVE.ORG link : CVE-2015-2802


JSON object : View

Products Affected

hp

  • asset_manager
  • asset_manager_cloudsystem_chargeback
  • sitescope

linux

  • linux_kernel

microsoft

  • windows

oracle

  • solaris
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor