CVE-2015-4000The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CWE-310CWE-295
Proof of concept only
A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | ✨ HAProxy ve Keepalived konusunu load balancer ve cluster'a ek olarak güvenlik(zayıf SSL/Kripto Kullanımı (LOGJAM) (CVE-2015-4000) zafiyeti önlemi) ve yüksek yüklere karşı ele alır. | 6 | 2021-04-24 |
A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
CISA-ADP | Secondary | published |
| CVSS 3.0 | 3.7 | LOW | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
NVD | Primary | |
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:N/I:P/A:N |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update January 2021 ↗ | CPU | 2021-Q1 | Oracle Enterprise Manager / User Interface (OpenSSL) (12.4.0.0) |
| Oracle Critical Patch Update April 2016 ↗ | CPU | 2016-Q2 | Oracle Sun Systems Products Suite / XCP Firmware (XCP prior to XCP 1121) |
| Oracle Critical Patch Update January 2016 ↗ | CPU | 2016-Q1 | Oracle Virtualization / OpenSSL (4.63, 4.71, 5.2) |
| Oracle Critical Patch Update October 2015 ↗ | CPU | 2015-Q4 | Oracle Communications Applications / Oracle Communications Messaging Server (7.0.5, 8.0) Oracle Sun Systems Products Suite / Fujitsu M10-1, M10-4, M10-4S Servers (XCP prior to XCP 2271) |
| Oracle Critical Patch Update July 2015 ↗ | CPU | 2015-Q3 | Oracle Java SE / Java SE, JRockit, Java SE Embedded (Java SE 6u95, Java SE 7u80, Java SE 8u45, JRockit R28.3.6, Java SE Embedded 7u75, Java SE Embedded 8u33) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications Applications | Oracle Communications Messaging Server | 7.0.5, 8.0 | 7.0.5 · 8.0 |
| Oracle Enterprise Manager | User Interface (OpenSSL) | 12.4.0.0 | 12.4.0.0 |
| Oracle Java SE | Java SE, JRockit, Java SE Embedded | Java SE 6u95, Java SE 7u80, Java SE 8u45, JRockit R28.3.6, Java SE Embedded 7u75, Java SE Embedded 8u33 | 6.0.95.0 · 7.0.75.0 · 7.0.80.0 · 8.0.33.0 · 8.0.45.0 |
| Oracle Sun Systems Products Suite | Fujitsu M10-1, M10-4, M10-4S Servers | XCP prior to XCP 2271 | 2271 |
| Oracle Sun Systems Products Suite | XCP Firmware | XCP prior to XCP 1121 | 1121 |
| Oracle Virtualization | OpenSSL | 4.63, 4.71, 5.2 | 4.63 · 4.71 · 5.2 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apple | iphone os | generic | ≤ 8.3 |
| nvd | apple | mac os x | generic | ≤ 10.10.3 |
| nvd | apple | safari | generic | any version |
| nvd | canonical | ubuntu linux | generic | 12.04 · 14.04 · 14.10 · 15.04 |
| nvd | debian | debian linux | generic | 7.0 · 8.0 |
| nvd | chrome | generic | any version | |
| nvd | hp | hp-ux | generic | b.11.31 |
| nvd | ibm | content manager | generic | 8.5 |
| nvd | microsoft | internet explorer | generic | any version |
| nvd | mozilla | firefox | generic | any version · 38.1.0 · 39.0 |
| nvd | mozilla | firefox esr | generic | 31.8 |
| nvd | mozilla | firefox os | generic | 2.2 |
| nvd | mozilla | network security services | generic | 3.19 |
| nvd | mozilla | seamonkey | generic | 2.35 |
| nvd | mozilla | thunderbird | generic | 31.8 · 38.1 |
| nvd | openssl | openssl | generic | ≥ 1.0.1 and ≤ 1.0.1 · ≤ 1.0.1 · ≥ 1.0.2 and ≤ 1.0.2 |
| nvd | opera | opera browser | generic | any version |
| nvd | oracle | jdk | javase | 1.6.0:update95 · 1.7.0:update75 · 1.7.0:update80 · 1.8.0:update_33 · 1.8.0:update45 |
| nvd | oracle | jre | javase | 1.6.0:update_95 · 1.7.0:update_75 · 1.7.0:update_80 · 1.8.0:update_33 · 1.8.0:update_45 |
| nvd | oracle | jrockit | generic | r28.3.6 |
| nvd | oracle | sparc-opl service processor | generic | ≤ 1121 |
| nvd | suse | linux enterprise desktop | generic | 12 |
| nvd | suse | linux enterprise server | generic | 11.0:sp4 |
| nvd | suse | linux enterprise software development kit | generic | 12 |
| nvd | suse | suse linux enterprise server | generic | 12 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** USER INTERFACE (OPENSSL), SEE NOTE 4, HTTPS, SSL/TLS, NO AUTH REMOTE EXPLOIT, JSSE, SEE NOTE 2, SECURITY, XCP FIRMWARE, OPENSSL **Products:** M10-4, ORACLE COMMUNICATIONS MESSAGING SERVER, JROCKIT, ORACLE ENTERPRISE MANAGER, JAVA SE EMBEDDED, ORACLE VIRTUALIZATION, FUJITSU M10-1, M10-4S SERVERS, LOGJAM, ORACLE SUN SYSTEMS PRODUCTS SUITE, M5000, M8000, M4000, ORACLE SECURE GLOBAL DESKTOP, ENTERPRISE MANAGER OPS CENTER, M9000 SERVERS, ORACLE COMMUNICATIONS APPLICATIONS, JAVA SE, ORACLE JAVA SE, SPARC ENTERPRISE M3000
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2015:1228 | ADVISORY, RHSA-2015:1228 |
| https://access.redhat.com/security/cve/CVE-2015-4000 | REPORT, RHSA-2015:1228 |
| https://access.redhat.com/errata/RHSA-2015:1229 | ADVISORY, RHSA-2015:1229 |
| https://access.redhat.com/errata/RHSA-2015:1230 | ADVISORY, RHSA-2015:1230 |
| https://access.redhat.com/errata/RHSA-2015:1241 | ADVISORY, RHSA-2015:1241 |
| https://access.redhat.com/errata/RHSA-2015:1526 | ADVISORY, RHSA-2015:1526 |
| http://aix.software.ibm.com/aix/efixes/security/sendmail_advisory2.asc | Third Party Advisory |
| http://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgery | Third Party Advisory |
| http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc | Mailing List, Third Party Advisory |
| http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04876402 | Third Party Advisory |
| Published | 2015-05-21 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |