← Back

CVE-2015-4078

nvd nist
Published: Mar 23, 2017Modified: May 13, 2026

JSON object

Loading...
3.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 1.6 / Impact: 1.4
Source: NVD

Description

Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

Affected (12)

2 products
Cloudera Manager
Navigator
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Cloudera
Version 5.3.0
Version 5.3.1
Version 5.3.2
Version 5.3.3
Version 5.4.0
Version 5.4.1
Cloudera
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.3.0
Version 2.3.1

Timeline

No history available yet.