Alibaba Web Server contains a flaw that may allow a remote attacker to obtain the session keys. The issue is due to the 'genkey' utility creating RSA public keys with an exponent of 1. This results in the session key for each SSL session to a server running 'Alibaba' to be sent in the clear.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Public
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.