Vulnerability Report

CVE-2016-2183

Title: Redhat Jboss Enterprise Web Server Information Disclosure

Information Disclosure

Proof Of Concept

PoC Available for CVE-2016-2183

CWE Category CWE-200
Published Date Sep 01, 2016
Modified Date May 29, 2026
Exploit Status Available
Score 7.5 CVSS v3.1
Exploit Probability (EPSS)
40.99%

Vulnerability Summary

CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

Impacted Vendors

Reference Links

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.html http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html http://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.html http://rhn.redhat.com/errata/RHSA-2017-0336.html http://rhn.redhat.com/errata/RHSA-2017-0337.html http://rhn.redhat.com/errata/RHSA-2017-0338.html http://rhn.redhat.com/errata/RHSA-2017-0462.html http://seclists.org/fulldisclosure/2017/Jul/31 http://seclists.org/fulldisclosure/2017/May/105 http://seclists.org/fulldisclosure/2017/May/105 http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697 http://www-01.ibm.com/support/docview.wss?uid=swg21991482 http://www-01.ibm.com/support/docview.wss?uid=swg21995039 http://www.debian.org/security/2016/dsa-3673 http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-openssl-en http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html http://www.securityfocus.com/archive/1/539885/100/0/threaded http://www.securityfocus.com/archive/1/540341/100/0/threaded http://www.securityfocus.com/archive/1/541104/100/0/threaded http://www.securityfocus.com/archive/1/542005/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/539885/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/540129/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/540341/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/541104/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/542005/100/0/threaded http://www.securityfocus.com/bid/92630 http://www.securityfocus.com/bid/95568 http://www.securitytracker.com/id/1036696 http://www.splunk.com/view/SP-CAAAPSV http://www.splunk.com/view/SP-CAAAPUE http://www.ubuntu.com/usn/USN-3087-1 http://www.ubuntu.com/usn/USN-3087-2 http://www.ubuntu.com/usn/USN-3179-1 http://www.ubuntu.com/usn/USN-3194-1 http://www.ubuntu.com/usn/USN-3198-1 http://www.ubuntu.com/usn/USN-3270-1 http://www.ubuntu.com/usn/USN-3372-1 https://access.redhat.com/articles/2548661 https://access.redhat.com/errata/RHSA-2017:1216 https://access.redhat.com/errata/RHSA-2017:2708 https://access.redhat.com/errata/RHSA-2017:2709 https://access.redhat.com/errata/RHSA-2017:2710 https://access.redhat.com/errata/RHSA-2017:3113 https://access.redhat.com/errata/RHSA-2017:3114 https://access.redhat.com/errata/RHSA-2017:3239 https://access.redhat.com/errata/RHSA-2017:3240 https://access.redhat.com/errata/RHSA-2018:2123 https://access.redhat.com/errata/RHSA-2019:1245 https://access.redhat.com/errata/RHSA-2019:2859 https://access.redhat.com/errata/RHSA-2020:0451 https://access.redhat.com/security/cve/cve-2016-2183 https://blog.cryptographyengineering.com/2016/08/24/attack-of-week-64-bit-ciphers-in-tls/ https://bto.bluecoat.com/security-advisory/sa133 https://bugzilla.redhat.com/show_bug.cgi?id=1369383 https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf https://github.com/ssllabs/ssllabs-scan/issues/387#issuecomment-242514633 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05302448 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369403 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369415 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05385680 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390722 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390849 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_us https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05302448 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05309984 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05323116 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390849 https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312 https://kc.mcafee.com/corporate/index?page=content&id=SB10171 https://kc.mcafee.com/corporate/index?page=content&id=SB10186 https://kc.mcafee.com/corporate/index?page=content&id=SB10197 https://kc.mcafee.com/corporate/index?page=content&id=SB10215 https://kc.mcafee.com/corporate/index?page=content&id=SB10310 https://nakedsecurity.sophos.com/2016/08/25/anatomy-of-a-cryptographic-collision-the-sweet32-attack/ https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/ https://seclists.org/bugtraq/2018/Nov/21 https://security.gentoo.org/glsa/201612-16 https://security.gentoo.org/glsa/201701-65 https://security.gentoo.org/glsa/201707-01 https://security.netapp.com/advisory/ntap-20160915-0001/ https://security.netapp.com/advisory/ntap-20170119-0001/ https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158613 https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03286178 https://support.f5.com/csp/article/K13167034 https://sweet32.info/ https://wiki.opendaylight.org/view/Security_Advisories https://www.arista.com/en/support/advisories-notices/security-advisories/1749-security-advisory-24 https://www.exploit-db.com/exploits/42091/ https://www.ietf.org/mail-archive/web/tls/current/msg04560.html https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008 https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2016/august/new-practical-attacks-on-64-bit-block-ciphers-3des-blowfish/ https://www.openssl.org/blog/blog/2016/08/24/sweet32/ https://www.oracle.com/security-alerts/cpuapr2020.html https://www.oracle.com/security-alerts/cpujan2020.html https://www.oracle.com/security-alerts/cpujul2020.html https://www.oracle.com/security-alerts/cpuoct2020.html https://www.oracle.com/security-alerts/cpuoct2021.html https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html https://www.sigsac.org/ccs/CCS2016/accepted-papers/ https://www.tenable.com/security/tns-2016-16 https://www.tenable.com/security/tns-2016-20 https://www.tenable.com/security/tns-2016-21 https://www.tenable.com/security/tns-2017-09 https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.html http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.html http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html http://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.html http://rhn.redhat.com/errata/RHSA-2017-0336.html http://rhn.redhat.com/errata/RHSA-2017-0337.html http://rhn.redhat.com/errata/RHSA-2017-0338.html http://rhn.redhat.com/errata/RHSA-2017-0462.html http://seclists.org/fulldisclosure/2017/Jul/31 http://seclists.org/fulldisclosure/2017/May/105 http://seclists.org/fulldisclosure/2017/May/105 http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697 http://www-01.ibm.com/support/docview.wss?uid=swg21991482 http://www-01.ibm.com/support/docview.wss?uid=swg21995039 http://www.debian.org/security/2016/dsa-3673 http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-openssl-en http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html http://www.securityfocus.com/archive/1/539885/100/0/threaded http://www.securityfocus.com/archive/1/540341/100/0/threaded http://www.securityfocus.com/archive/1/541104/100/0/threaded http://www.securityfocus.com/archive/1/542005/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/539885/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/540129/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/540341/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/541104/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/542005/100/0/threaded http://www.securityfocus.com/bid/92630 http://www.securityfocus.com/bid/95568 http://www.securitytracker.com/id/1036696 http://www.splunk.com/view/SP-CAAAPSV http://www.splunk.com/view/SP-CAAAPUE http://www.ubuntu.com/usn/USN-3087-1 http://www.ubuntu.com/usn/USN-3087-2 http://www.ubuntu.com/usn/USN-3179-1 http://www.ubuntu.com/usn/USN-3194-1 http://www.ubuntu.com/usn/USN-3198-1 http://www.ubuntu.com/usn/USN-3270-1 http://www.ubuntu.com/usn/USN-3372-1 https://access.redhat.com/articles/2548661 https://access.redhat.com/errata/RHSA-2017:1216 https://access.redhat.com/errata/RHSA-2017:2708 https://access.redhat.com/errata/RHSA-2017:2709 https://access.redhat.com/errata/RHSA-2017:2710 https://access.redhat.com/errata/RHSA-2017:3113 https://access.redhat.com/errata/RHSA-2017:3114 https://access.redhat.com/errata/RHSA-2017:3239 https://access.redhat.com/errata/RHSA-2017:3240 https://access.redhat.com/errata/RHSA-2018:2123 https://access.redhat.com/errata/RHSA-2019:1245 https://access.redhat.com/errata/RHSA-2019:2859 https://access.redhat.com/errata/RHSA-2020:0451 https://access.redhat.com/security/cve/cve-2016-2183 https://blog.cryptographyengineering.com/2016/08/24/attack-of-week-64-bit-ciphers-in-tls/ https://bto.bluecoat.com/security-advisory/sa133 https://bugzilla.redhat.com/show_bug.cgi?id=1369383 https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf https://github.com/ssllabs/ssllabs-scan/issues/387#issuecomment-242514633 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05302448 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369403 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369415 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05385680 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390722 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390849 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_us https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05302448 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05309984 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05323116 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390849 https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312 https://kc.mcafee.com/corporate/index?page=content&id=SB10171 https://kc.mcafee.com/corporate/index?page=content&id=SB10186 https://kc.mcafee.com/corporate/index?page=content&id=SB10197 https://kc.mcafee.com/corporate/index?page=content&id=SB10215 https://kc.mcafee.com/corporate/index?page=content&id=SB10310 https://nakedsecurity.sophos.com/2016/08/25/anatomy-of-a-cryptographic-collision-the-sweet32-attack/ https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/ https://seclists.org/bugtraq/2018/Nov/21 https://security.gentoo.org/glsa/201612-16 https://security.gentoo.org/glsa/201701-65 https://security.gentoo.org/glsa/201707-01 https://security.netapp.com/advisory/ntap-20160915-0001/ https://security.netapp.com/advisory/ntap-20170119-0001/ https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158613 https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03286178 https://support.f5.com/csp/article/K13167034 https://sweet32.info/ https://wiki.opendaylight.org/view/Security_Advisories https://www.arista.com/en/support/advisories-notices/security-advisories/1749-security-advisory-24 https://www.exploit-db.com/exploits/42091/ https://www.ietf.org/mail-archive/web/tls/current/msg04560.html https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008 https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2016/august/new-practical-attacks-on-64-bit-block-ciphers-3des-blowfish/ https://www.openssl.org/blog/blog/2016/08/24/sweet32/ https://www.oracle.com/security-alerts/cpuapr2020.html https://www.oracle.com/security-alerts/cpujan2020.html https://www.oracle.com/security-alerts/cpujul2020.html https://www.oracle.com/security-alerts/cpuoct2020.html https://www.oracle.com/security-alerts/cpuoct2021.html https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html https://www.sigsac.org/ccs/CCS2016/accepted-papers/ https://www.tenable.com/security/tns-2016-16 https://www.tenable.com/security/tns-2016-20 https://www.tenable.com/security/tns-2016-21 https://www.tenable.com/security/tns-2017-09 https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue https://www.vicarius.io/vsociety/posts/cve-2016-2183-detection-sweet32-vulnerability https://www.vicarius.io/vsociety/posts/cve-2016-2183-mitigate-sweet32-vulnerability
CVSS v3.1
Source Entity [email protected]
Severity HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
Source Entity 134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:N/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2016-2183 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/ZakyHermawan/Simple-Sweet32
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Stack

No specific products linked.