The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.
https://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.12/