vulnerability

IBM HTTP Server: CVE-2015-0138: A vulnerability in various IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Sep 7, 2022
Added
Sep 7, 2022
Modified
Nov 20, 2025

Description

A vulnerability in various IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections. An IBM SSL/TLS client implementation could accept the use of an RSA temporary key in a non-export RSA key exchange ciphersuite. This could allow a remote attacker using man-in-the-middle techniques to facilitate brute-force decryption of TLS/SSL traffic between vulnerable clients and servers.
This vulnerability is also known as the FREAK attack.

Solutions

ibm-http_server-apply-interim-fix-pi36417-for-8_5ibm-http_server-apply-interim-fix-pi36417-for-8_0ibm-http_server-apply-interim-fix-pi36417-for-7_0ibm-http_server-apply-interim-fix-pi36417-for-6_1ibm-http_server-apply-interim-fix-pi36417-for-6_0ibm-http_server-apply-fix-pack-8_5_5_6ibm-http_server-apply-fix-pack-8_0_0_11ibm-http_server-apply-fix-pack-7_0_0_39ibm-http_server-apply-fix-pack-6_1_0_48ibm-http_server-apply-fix-pack-6_0_2_44
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.