Oracle HTTP Server Inadequate Encryption Strength Vulnerability - CVE-2013-2566 - Vulnerability Database

Oracle HTTP Server Inadequate Encryption Strength Vulnerability - CVE-2013-2566

Medium
Reference: CVE-2013-2566
Title: Oracle HTTP Server Inadequate Encryption Strength Vulnerability
Overview:

The RC4 algorithm as used in the TLS protocol and SSL protocol has many single-byte biases which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.