CVE-2014-0852

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
16/08/2014
Last modified:
12/04/2025

Description

IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:*:*:*:*:*:*:*:* 4.0.2.15 (including)
cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:5.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:6.0.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:websphere_datapower_soa_appliance_firmware:6.0.1:*:*:*:*:*:*:*
cpe:2.3:h:ibm:websphere_datapower_soa_appliance:-:*:*:*:*:*:*:*