Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2808

52
FAUCET Score

CVE-2015-2808, also known as the "Bar Mitzvah" issue, describes a weakness in the RC4 algorithm used in TLS and SSL protocols, making it susceptible to plaintext-recovery attacks. This vulnerability affects a wide range of products from vendors including Canonical, Debian, IBM, Oracle, and Red Hat. With a CVSS score of 5.0, it is a medium-severity vulnerability that can be exploited remotely with low attack complexity, potentially leading to the compromise of initial bytes of encrypted data. While there is no evidence of active exploitation, nor readily available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, <= 3.9.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_application_session_controller:*:*:*:*:*:*:*:*
< 9.9.2CPE matchmatch criteria
cpe:2.3:a:oracle:communications_policy_management:*:*:*:*:*:*:*:*
11.1.1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:http_server:11.1.1.7.0:*:*:*:*:*:*:*
11.1.1.9.0CPE matchmatch criteria
cpe:2.3:a:oracle:http_server:11.1.1.9.0:*:*:*:*:*:*:*
12.1.3.0.0CPE matchmatch criteria
cpe:2.3:a:oracle:http_server:12.1.3.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
73.85%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.7385 is in the 100th percentile among its peer group of 61 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (35)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 6Fixed in: java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 7Fixed in: java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 7Fixed in: java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 7Fixed in: java-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 SupplementaryFixed in: java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 SupplementaryFixed in: java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 SupplementaryFixed in: java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: java-1.8.0-openjdk-1:1.8.0.51-1.b16.ael7b_1
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 5.6Fixed in: java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 5.7Fixed in: java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 7Fixed in: java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.ael7b_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: java-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.el7_1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: gnutls
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl

Vendor Advisories (1)

redhatCVE-2015-2808Moderate

SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher

Mar 30, 2015

References

h20564.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-06/msg00013.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-06/msg00014.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-06/msg00015.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-06/msg00022.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-06/msg00031.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-07/msg00039.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-07/msg00040.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-07/msg00046.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-07/msg00047.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-12/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-12/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00005.html
Mailing ListThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
rhn.redhat.com / errata/RHSA-2015-1006.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1007.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1020.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1021.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1091.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1228.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1229.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1230.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1241.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1242.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1243.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1526.html
Third Party Advisory
h20564.www2.hp.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
kb.juniper.net / JSA10783
Third Party Advisory
kc.mcafee.com / corporate/index
Broken Link
security.gentoo.org / glsa/201512-10
Third Party Advisory
www-947.ibm.com / support/entry/portal/docdisplay
Third Party Advisory
blackhat.com / docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf
Technical DescriptionThird Party Advisory
secpod.com / blog/cve-2015-2808-bar-mitzvah-attack-in-rc4-2
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www1.huawei.com / en/security/psirt/security-bulletins/security-advisories/hw-454055.htm
Third Party Advisory
www-304.ibm.com / support/docview.wss
Third Party Advisory
www-304.ibm.com / support/docview.wss
Third Party Advisory
www-304.ibm.com / support/docview.wss
Third Party Advisory
debian.org / security/2015/dsa-3316
Third Party Advisory
debian.org / security/2015/dsa-3339
Third Party Advisory
huawei.com / en/psirt/security-advisories/hw-454055
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuapr2016v3-2985753.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujan2018-3236628.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
Third Party Advisory
oracle.com / technetwork/topics/security/cpujul2015-2367936.html
Third Party Advisory
securityfocus.com / bid/73684
Third Party AdvisoryVDB Entry
securityfocus.com / bid/91787
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032599
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032600
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032707
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032708
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032734
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032788
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032858
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032868
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032910
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032990
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033071
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033072
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033386
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033415
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033431
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033432
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033737
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033769
Third Party AdvisoryVDB Entry
securitytracker.com / id/1036222
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2696-1
Third Party Advisory
ubuntu.com / usn/USN-2706-1
Third Party Advisory