CVE-2011-3389The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
CWE-326
Proof of concept only
A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | :muscle: Proof Of Concept of the BEAST attack against SSL/TLS CVE-2011-3389 :muscle: | 80 | 2015-03-28 |
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address. |
AV:N/AC:M/Au:N/C:P/I:N/A:N
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | Primary | published |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update January 2015 ↗ | CPU | 2015-Q1 | Oracle Fusion Middleware / Oracle Security Service (OHS: 12.1.2, FMW: 12.1.3) |
| Oracle Critical Patch Update October 2013 ↗ | CPU | 2013-Q4 | Oracle Database Server / Oracle Security Service (11.1.0.7, 11.2.0.2, 11.2.0.3) Oracle Fusion Middleware / Oracle Security Service (FMW: 11.1.1.6, 11.1.1.7 Forms: 11.1.2.1) |
| Java SE CPU Oct 2011 ↗ | CPU | 2011-Q4 | Oracle JDK, JRE and JRockit / Java Runtime Environment (JDK and JRE 7, 6 Update 27 and before, 5.0 Update 31 and before, 1.4.2_33 and before. JRockit R28.1.4 and before) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Database Server | Oracle Security Service | 11.1.0.7, 11.2.0.2, 11.2.0.3 | 11.1.0.7 · 11.2.0.2 · 11.2.0.3 |
| Oracle Fusion Middleware | Oracle Security Service | FMW: 11.1.1.6, 11.1.1.7 Forms: 11.1.2.1 | 11.1.1.6 · 11.1.1.7.11.1 · 12.1.2 · 12.1.3 |
| Oracle JDK, JRE and JRockit | Java Runtime Environment | JDK and JRE 7, 6 Update 27 and before, 5.0 Update 31 and before, 1.4.2_33 and before. JRockit R28.1.4 and before | 7 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | canonical | ubuntu linux | generic | 10.04 · 10.10 · 11.04 · 11.10 |
| nvd | debian | debian linux | generic | 5.0 · 6.0 |
| nvd | chrome | generic | any version | |
| nvd | haxx | curl | generic | ≥ 7.10.6 and ≤ 7.23.1 |
| nvd | microsoft | internet explorer | generic | any version |
| nvd | microsoft | windows | generic | any version |
| nvd | mozilla | firefox | generic | any version |
| nvd | opera | opera browser | generic | any version |
| nvd | redhat | enterprise linux desktop | generic | 5.0 · 6.0 |
| nvd | redhat | enterprise linux eus | generic | 6.2 |
| nvd | redhat | enterprise linux server | generic | 5.0 · 6.0 |
| nvd | redhat | enterprise linux server aus | generic | 6.2 |
| nvd | redhat | enterprise linux workstation | generic | 5.0 · 6.0 |
| nvd | siemens | simatic rf615r firmware | generic | < 3.2.1 |
| nvd | siemens | simatic rf68xr firmware | generic | < 3.2.1 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** SEE NOTE 4, HTTPS, SSL/TLS, NO AUTH REMOTE EXPLOIT, JSSE **Products:** SSL/TLS
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2011:1380 | ADVISORY, RHSA-2011:1380 |
| https://access.redhat.com/security/cve/CVE-2011-3389 | REPORT, RHSA-2011:1380 |
| http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/ | Third Party Advisory |
| http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx | Third Party Advisory |
| http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx | Third Party Advisory |
| http://curl.haxx.se/docs/adv_20120124B.html | Third Party Advisory |
| http://downloads.asterisk.org/pub/security/AST-2016-001.html | Third Party Advisory |
| http://ekoparty.org/2011/juliano-rizzo.php | Broken Link |
| http://eprint.iacr.org/2004/111 | Third Party Advisory |
| http://eprint.iacr.org/2006/136 | Third Party Advisory |
| Published | 2011-09-06 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |