VDB

RHSA-2014%3A0896

RHSA-2014%3A0896 PUBLISHED CVSS 5.099999904632568 MEDIUM

It was discovered that bouncycastle leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle.

Risk Scores

CVSS 2.0
5.099999904632568

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Web Framework Kit 2.6

Timeline

  • Jul 16, 2014 CVE Published
  • Jan 28, 2026 CVE Updated
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›