Patch available for SSL 3.0 “POODLE” Security Vulnerability (CVE-2014-3566)
This patch addresses the vulnerability discovered in the SSL 3.0. A flaw was discovered that makes it easy for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack.
Applying the patch
- Enable SSH on the target component.
- Log on to your system using the clisystem account.
Run the following command:
install https://deviceupdates.bmc.com/downloads/FLAM-143-1.0.2.zip- Repeat for each remaining component.
After applying the patch
Re-establish SSH settings for all applicable components, as described in the following topics:
- Enhancing-access-management-Collector
- Enhancing-access-management-Analyzer
- Adding-components-to-the-Console (PAE)
- Controlling-remote-access-to-the-command-line-interface
If a problem occurs
If you encountered problems during the installation of the patch or if you could not access the internet to run the installation, contact BMC Customer Support.
Related topics
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*