VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago

CVE-2016-2183

7.5 High Out of RASP scope

Description

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CWE-200 · Information exposure

Exploitation Status

Proof of concept only

A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment exploitation: poc CISA concluded an exploit has been demonstrated, typically from a vendor advisory, which leaves no artifact to index. Automatable: yes, technical impact: partial.
  • Indexed PoC 1 indexed Published artifacts you can open, in GitHub PoC; first seen 2025-12-13.
  • EPSS 96% chance in 30 days A model prediction, not an observation. Higher than 100% of all scored CVEs.

1 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) 2025-12-13

Waratek Defense Posture

Out of RASP scope

A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.

  • Protection none
  • Action not-needed none
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N NVD Primary published
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CISA-ADP Secondary
CVSS 2.0 5.0 no band published AV:N/AC:L/Au:N/C:P/I:N/A:N NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update October 2021 CPU 2021-Q4 Oracle Siebel CRM / EAI, SWSE (OpenSSL) (21.9 and prior)
Oracle Critical Patch Update October 2017 CPU 2017-Q4 Oracle Fusion Middleware / OSSL Module (11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0)
Oracle Critical Patch Update July 2017 CPU 2017-Q3 Oracle Database Server / Real Application Clusters (11.2.0.4, 12.1.0.2)
Oracle Critical Patch Update January 2017 CPU 2017-Q1 Oracle Java SE / Java SE, Java SE Embedded (Java SE: 6u131, 7u121, 8u112; Java SE Embedded: 8u111)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Database Server Real Application Clusters 11.2.0.4, 12.1.0.2 11.2.0.4 · 12.1.0.2
Oracle Fusion Middleware OSSL Module 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 11.1.1.7.0 · 11.1.1.9.0 · 12.1.3.0.0 · 12.2.1.1.0 · 12.2.1.2.0
Oracle Java SE Java SE, Java SE Embedded Java SE: 6u131, 7u121, 8u112; Java SE Embedded: 8u111 6.0.131.0 · 7.0.121.0 · 8.0.111.0 · 8.0.112.0
Oracle Siebel CRM EAI, SWSE (OpenSSL) 21.9 and prior

🖥️ Product CPEs & Version Ranges

9 product(s) over 45 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd cisco content security management appliance generic 9.6.6-068 · 9.7.0-006
nvd nodejs node.js generic ≥ 0.10.0 and < 0.10.47 · ≥ 0.12.0 and < 0.12.16 · ≥ 4.0.0 and < 4.1.2 · ≥ 4.2.0 and < 4.6.0 · ≥ 6.0.0 and < 6.7.0
nvd openssl openssl generic 1.0.1a · 1.0.1b · 1.0.1c · 1.0.1d · 1.0.1e · 1.0.1f · 1.0.1g · 1.0.1h · 1.0.1i · 1.0.1j · 1.0.1k · 1.0.1l · 1.0.1m · 1.0.1n · 1.0.1o · 1.0.1p · 1.0.1q · 1.0.1r · 1.0.1t · 1.0.2a · 1.0.2b · 1.0.2c · 1.0.2d · 1.0.2e · 1.0.2f · 1.0.2h
nvd oracle database generic 11.2.0.4 · 12.1.0.2
nvd python python generic ≥ 2.7.0 and < 2.7.13 · ≥ 3.4.0 and < 3.4.7 · ≥ 3.5.0 and < 3.5.3
nvd redhat enterprise linux generic 5.0 · 6.0 · 7.0
nvd redhat jboss enterprise application platform generic 6.0.0
nvd redhat jboss enterprise web server generic 1.0.0 · 2.0.0
nvd redhat jboss web server generic 3.0

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** HTTPS, SWEET32, MULTIPLE, SSL/TLS, SEE NOTE 3, NO AUTH REMOTE EXPLOIT, OSSL MODULE, TLS, SWSE (OPENSSL), EAI **Products:** TLS SSH, SSL/TLS, DES CIPHER, IPSEC PROTOCOLS, SIEBEL UI FRAMEWORK, ORACLE SIEBEL CRM

References

URLTags
https://access.redhat.com/errata/RHSA-2017:0462 ADVISORY, RHSA-2017:0462
https://bugzilla.redhat.com/show_bug.cgi?id=1369383 REPORT, RHSA-2017:0462
https://access.redhat.com/security/cve/CVE-2016-2183 REPORT, RHSA-2017:0462
https://access.redhat.com/errata/RHSA-2016:1940 ARTICLE, RHSA-2017:0462
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html Mailing List, Third Party Advisory

Timeline

Published 2016-09-01 Last modified 2026-06-17
Published2016-09-01By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.