CVE-2015-3197 is a medium-severity vulnerability affecting OpenSSL versions 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f, as well as Oracle products utilizing these OpenSSL versions. It allows man-in-the-middle attackers to bypass cryptographic protections by enabling the use of disabled ciphers in SSLv2 traffic. The vulnerability has a CVSS score of 5.9, indicating a network-based attack with high impact on confidentiality, but high attack complexity. Although there is no known active exploitation, exploit code, or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, suggesting a notable level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:oracle:exalogic_infrastructure:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:oracle:exalogic_infrastructure:2.0:*:*:*:*:*:*:* | ||
8.53CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:* | ||
8.54CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.