VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago

CVE-2015-4000

3.7 Low Out of RASP scope

Description

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CWE-310CWE-295

Exploitation Status

Proof of concept only

A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment exploitation: none
  • Indexed PoC 1 indexed Published artifacts you can open, in GitHub PoC; first seen 2021-04-24.
  • EPSS 100% chance in 30 days A model prediction, not an observation. Higher than 99.9% of all scored CVEs.
IndexArtifactStarsFirst seen
GitHub PoC ✨ HAProxy ve Keepalived konusunu load balancer ve cluster'a ek olarak güvenlik(zayıf SSL/Kripto Kullanımı (LOGJAM) (CVE-2015-4000) zafiyeti önlemi) ve yüksek yüklere karşı ele alır. 6 2021-04-24

Waratek Defense Posture

Out of RASP scope

A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.

  • Protection none
  • Action not-needed none
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products

CVSS

3.7 LOW v3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CISA-ADP Secondary published
CVSS 3.0 3.7 LOW CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N NVD Primary
CVSS 2.0 4.3 no band published AV:N/AC:M/Au:N/C:N/I:P/A:N NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update January 2021 CPU 2021-Q1 Oracle Enterprise Manager / User Interface (OpenSSL) (12.4.0.0)
Oracle Critical Patch Update April 2016 CPU 2016-Q2 Oracle Sun Systems Products Suite / XCP Firmware (XCP prior to XCP 1121)
Oracle Critical Patch Update January 2016 CPU 2016-Q1 Oracle Virtualization / OpenSSL (4.63, 4.71, 5.2)
Oracle Critical Patch Update October 2015 CPU 2015-Q4 Oracle Communications Applications / Oracle Communications Messaging Server (7.0.5, 8.0)
Oracle Sun Systems Products Suite / Fujitsu M10-1, M10-4, M10-4S Servers (XCP prior to XCP 2271)
Oracle Critical Patch Update July 2015 CPU 2015-Q3 Oracle Java SE / Java SE, JRockit, Java SE Embedded (Java SE 6u95, Java SE 7u80, Java SE 8u45, JRockit R28.3.6, Java SE Embedded 7u75, Java SE Embedded 8u33)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Applications Oracle Communications Messaging Server 7.0.5, 8.0 7.0.5 · 8.0
Oracle Enterprise Manager User Interface (OpenSSL) 12.4.0.0 12.4.0.0
Oracle Java SE Java SE, JRockit, Java SE Embedded Java SE 6u95, Java SE 7u80, Java SE 8u45, JRockit R28.3.6, Java SE Embedded 7u75, Java SE Embedded 8u33 6.0.95.0 · 7.0.75.0 · 7.0.80.0 · 8.0.33.0 · 8.0.45.0
Oracle Sun Systems Products Suite Fujitsu M10-1, M10-4, M10-4S Servers XCP prior to XCP 2271 2271
Oracle Sun Systems Products Suite XCP Firmware XCP prior to XCP 1121 1121
Oracle Virtualization OpenSSL 4.63, 4.71, 5.2 4.63 · 4.71 · 5.2

🖥️ Product CPEs & Version Ranges

25 product(s) over 42 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apple iphone os generic ≤ 8.3
nvd apple mac os x generic ≤ 10.10.3
nvd apple safari generic any version
nvd canonical ubuntu linux generic 12.04 · 14.04 · 14.10 · 15.04
nvd debian debian linux generic 7.0 · 8.0
nvd google chrome generic any version
nvd hp hp-ux generic b.11.31
nvd ibm content manager generic 8.5
nvd microsoft internet explorer generic any version
nvd mozilla firefox generic any version · 38.1.0 · 39.0
nvd mozilla firefox esr generic 31.8
nvd mozilla firefox os generic 2.2
nvd mozilla network security services generic 3.19
nvd mozilla seamonkey generic 2.35
nvd mozilla thunderbird generic 31.8 · 38.1
nvd openssl openssl generic ≥ 1.0.1 and ≤ 1.0.1 · ≤ 1.0.1 · ≥ 1.0.2 and ≤ 1.0.2
nvd opera opera browser generic any version
nvd oracle jdk javase 1.6.0:update95 · 1.7.0:update75 · 1.7.0:update80 · 1.8.0:update_33 · 1.8.0:update45
nvd oracle jre javase 1.6.0:update_95 · 1.7.0:update_75 · 1.7.0:update_80 · 1.8.0:update_33 · 1.8.0:update_45
nvd oracle jrockit generic r28.3.6
nvd oracle sparc-opl service processor generic ≤ 1121
nvd suse linux enterprise desktop generic 12
nvd suse linux enterprise server generic 11.0:sp4
nvd suse linux enterprise software development kit generic 12
nvd suse suse linux enterprise server generic 12

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** USER INTERFACE (OPENSSL), SEE NOTE 4, HTTPS, SSL/TLS, NO AUTH REMOTE EXPLOIT, JSSE, SEE NOTE 2, SECURITY, XCP FIRMWARE, OPENSSL **Products:** M10-4, ORACLE COMMUNICATIONS MESSAGING SERVER, JROCKIT, ORACLE ENTERPRISE MANAGER, JAVA SE EMBEDDED, ORACLE VIRTUALIZATION, FUJITSU M10-1, M10-4S SERVERS, LOGJAM, ORACLE SUN SYSTEMS PRODUCTS SUITE, M5000, M8000, M4000, ORACLE SECURE GLOBAL DESKTOP, ENTERPRISE MANAGER OPS CENTER, M9000 SERVERS, ORACLE COMMUNICATIONS APPLICATIONS, JAVA SE, ORACLE JAVA SE, SPARC ENTERPRISE M3000

References

URLTags
https://access.redhat.com/errata/RHSA-2015:1228 ADVISORY, RHSA-2015:1228
https://access.redhat.com/security/cve/CVE-2015-4000 REPORT, RHSA-2015:1228
https://access.redhat.com/errata/RHSA-2015:1229 ADVISORY, RHSA-2015:1229
https://access.redhat.com/errata/RHSA-2015:1230 ADVISORY, RHSA-2015:1230
https://access.redhat.com/errata/RHSA-2015:1241 ADVISORY, RHSA-2015:1241
https://access.redhat.com/errata/RHSA-2015:1526 ADVISORY, RHSA-2015:1526
http://aix.software.ibm.com/aix/efixes/security/sendmail_advisory2.asc Third Party Advisory
http://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgery Third Party Advisory
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc Mailing List, Third Party Advisory
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04876402 Third Party Advisory

Timeline

Published 2015-05-21 Last modified 2026-06-17
Published2015-05-21By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.