SSL Poodle Vulnerability (CVE-2014-3566)
A security related design flaw in SSL v3.0, called "Poodle", has been announced by Google.
- The vulnerability has been assigned the ID CVE-2014-3566.
- SSL v3.0 is a legacy secure transport protocol superseded by TLS.
- The vulnerability affects SSL v3.0 only; no version of TLS is affected.
Oracle recommends disabling SSL v3.0 in all products.
Doc ID 1935500.1 has been published with regard to this SSL issue and will be actively updated with instructions on how to disable SSL 3.0 in different products.
Regards,
Alan Hargreaves
--
Senior Principal Technical Support Engineer
Solaris and Network
Oracle Support