SSLv3 Vulnerability in Cloudera Navigator by Cloudera
CVE-2015-4078

3.1LOW

Key Information:

Vendor

Cloudera

Vendor
CVE Published:
23 March 2017

What is CVE-2015-4078?

Cloudera Navigator versions 2.2.x prior to 2.2.4 and 2.3.x prior to 2.3.3 are susceptible to a vulnerability due to the use of SSLv3 in SSL/TLS configurations. This flaw enables man-in-the-middle attackers to exploit a padding-oracle attack, allowing them to gain access to sensitive cleartext data. The vulnerability is related to the infamous POODLE attack and necessitates immediate attention and remediation to enhance the security posture of affected systems.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.