Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3467
HistoryFeb 07, 2017 - 12:05 a.m.

Information Disclosure

2017-02-0700:05:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
31

0.975 High

EPSS

Percentile

100.0%

OpenSSL is vulnerable to information disclosure. This is possible because the SSL protocol 3.0 uses a nondeterministic CBC padding allowing attackers to perform man-in-the-middle (MitM) attacks. This is also known as the POODLE issue.

CPENameOperatorVersion
opensslle1.0.109
opensslle1.0.109

References