Technical bulletins

This section contains information about updates for the BMC PATROL for Internet Server that are not related to flashes, service packs, or patches.

Poodle SSLv3 vulnerability impact on BMC PATROL for Internet Servers

BMC PATROL for Internet Server is a client based application. To establish a successful connection with the target server, the KM uses the same secure protocol used by the target server. If the server requests to use SSLv3 protocol during the handshake operation, the KM uses SSLv3 protocol to establish a connection.

BMC PATROL for Internet Server uses Mozilla Firefox Network Security Services (NSS) libraries. A security vulnerability related to the SSLv3 protocol has been detected. To address this vulnerability, Mozilla Firefox has disabled the Secure Socket Layer (SSL) v3.0 protocol. Therefore, BMC PATROL for Internet Server has discontinued the support of SSLv3 protocol and will not be able to monitor Web URLs that require this protocol. For more information, see https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/. 

 


Was this page helpful? Yes No Submitting... Thank you

Comments