The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
2013-03-15T21:55:01.047
2025-04-11T00:51:21.963
Deferred
CVSSv3.0: 5.9 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | oracle | communications_application_session_controller | ≤ 3.9.1 | Yes |
| Application | oracle | http_server | 11.1.1.7.0 | Yes |
| Application | oracle | http_server | 11.1.1.9.0 | Yes |
| Application | oracle | http_server | 12.1.3.0.0 | Yes |
| Application | oracle | http_server | 12.2.1.1.0 | Yes |
| Application | oracle | http_server | 12.2.1.2.0 | Yes |
| Operating System | oracle | integrated_lights_out_manager_firmware | ≤ 3.2.11 | Yes |
| Operating System | oracle | integrated_lights_out_manager_firmware | ≤ 4.0.4 | Yes |
| Operating System | fujitsu | sparc_enterprise_m3000_firmware | < xcp_1121 | Yes |
| Hardware | fujitsu | sparc_enterprise_m3000 | - | No |
| Operating System | fujitsu | sparc_enterprise_m4000_firmware | < xcp_1121 | Yes |
| Hardware | fujitsu | sparc_enterprise_m4000 | - | No |
| Operating System | fujitsu | sparc_enterprise_m5000_firmware | < xcp_1121 | Yes |
| Hardware | fujitsu | sparc_enterprise_m5000 | - | No |
| Operating System | fujitsu | sparc_enterprise_m8000_firmware | < xcp_1121 | Yes |
| Hardware | fujitsu | sparc_enterprise_m8000 | - | No |
| Operating System | fujitsu | sparc_enterprise_m9000_firmware | < xcp_1121 | Yes |
| Hardware | fujitsu | sparc_enterprise_m9000 | - | No |
| Operating System | fujitsu | m10-1_firmware | < xcp2280 | Yes |
| Hardware | fujitsu | m10-1 | - | No |
| Operating System | fujitsu | m10-4_firmware | < xcp2280 | Yes |
| Hardware | fujitsu | m10-4 | - | No |
| Operating System | fujitsu | m10-4s_firmware | < xcp2280 | Yes |
| Hardware | fujitsu | m10-4s | - | No |
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 12.10 | Yes |
| Operating System | canonical | ubuntu_linux | 13.04 | Yes |
| Operating System | canonical | ubuntu_linux | 13.10 | Yes |
| Application | mozilla | firefox | < 17.0.11 | Yes |
| Application | mozilla | firefox | < 25.0.1 | Yes |
| Application | mozilla | firefox | < 24.1.1 | Yes |
| Application | mozilla | seamonkey | < 2.22.1 | Yes |
| Application | mozilla | thunderbird | < 24.1.1 | Yes |
| Application | mozilla | thunderbird_esr | < 17.0.11 | Yes |