3.1
CVSSv3

CVE-2015-4078

Published: 23/03/2017 Updated: 28/03/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 3.1 | Impact Score: 1.4 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Cloudera Navigator 2.2.x prior to 2.2.4 and 2.3.x prior to 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle malicious users to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

Vulnerable Product Search on Vulmon Subscribe to Product

cloudera navigator 2.2.2

cloudera cloudera manager 5.4.0

cloudera cloudera manager 5.3.0

cloudera cloudera manager 5.3.2

cloudera cloudera manager 5.3.3

cloudera navigator 2.2.3

cloudera navigator 2.3.0

cloudera navigator 2.3.1

cloudera navigator 2.2.0

cloudera navigator 2.2.1

cloudera cloudera manager 5.4.1

cloudera cloudera manager 5.3.1