{"id":"CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.","cvssScore":4.3,"cvssVersion":"2.0","cvssVector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":4.3,"vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-326"],"resolved":"NOT-APPLICABLE","published":"2011-09-06","lastModified":"2026-06-16","affectedProducts":[{"vendor":"google","product":"chrome"},{"vendor":"microsoft","product":"internet explorer"},{"vendor":"mozilla","product":"firefox"},{"vendor":"opera","product":"opera browser"},{"vendor":"microsoft","product":"windows"},{"vendor":"siemens","product":"simatic rf68xr firmware","versionEnd":"\u003c3.2.1"},{"vendor":"siemens","product":"simatic rf615r firmware","versionEnd":"\u003c3.2.1"},{"vendor":"haxx","product":"curl","versionStart":"\u003e=7.10.6","versionEnd":"\u003c=7.23.1"},{"vendor":"redhat","product":"enterprise linux desktop","version":"5.0"},{"vendor":"redhat","product":"enterprise linux desktop","version":"6.0"},{"vendor":"redhat","product":"enterprise linux eus","version":"6.2"},{"vendor":"redhat","product":"enterprise linux server","version":"5.0"},{"vendor":"redhat","product":"enterprise linux server","version":"6.0"},{"vendor":"redhat","product":"enterprise linux server aus","version":"6.2"},{"vendor":"redhat","product":"enterprise linux workstation","version":"5.0"},{"vendor":"redhat","product":"enterprise linux workstation","version":"6.0"},{"vendor":"debian","product":"debian linux","version":"5.0"},{"vendor":"debian","product":"debian linux","version":"6.0"},{"vendor":"canonical","product":"ubuntu linux","version":"10.04"},{"vendor":"canonical","product":"ubuntu linux","version":"10.10"}],"totalAffectedProducts":15,"references":[{"url":"https://access.redhat.com/errata/RHSA-2011:1380","source":"redhat","tags":["ADVISORY","RHSA-2011:1380"]},{"url":"https://access.redhat.com/security/cve/CVE-2011-3389","source":"redhat","tags":["REPORT","RHSA-2011:1380"]},{"url":"http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://curl.haxx.se/docs/adv_20120124B.html","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://downloads.asterisk.org/pub/security/AST-2016-001.html","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://ekoparty.org/2011/juliano-rizzo.php","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"http://eprint.iacr.org/2004/111","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"http://eprint.iacr.org/2006/136","source":"cve@mitre.org","tags":["Third Party Advisory"]}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"NOT-APPLICABLE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update January 2015","releaseType":"CPU","quarter":"2015-Q1","url":"https://www.oracle.com/security-alerts/cpujan2015.html","products":[{"product":"Oracle Fusion Middleware","component":"Oracle Security Service","affectedVersions":"OHS: 12.1.2, FMW: 12.1.3"}]},{"advisory":"Oracle Critical Patch Update October 2013","releaseType":"CPU","quarter":"2013-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2013.html","products":[{"product":"Oracle Database Server","component":"Oracle Security Service","affectedVersions":"11.1.0.7, 11.2.0.2, 11.2.0.3"},{"product":"Oracle Fusion Middleware","component":"Oracle Security Service","affectedVersions":"FMW: 11.1.1.6, 11.1.1.7 Forms: 11.1.2.1"}]},{"advisory":"Java SE CPU Oct 2011","releaseType":"CPU","quarter":"2011-Q4","url":"https://www.oracle.com/security-alerts/javacpuoct2011.html","products":[{"product":"Oracle JDK, JRE and JRockit","component":"Java Runtime Environment","affectedVersions":"JDK and JRE 7, 6 Update 27 and before, 5.0 Update 31 and before, 1.4.2_33 and before. JRockit R28.1.4 and before"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** SEE NOTE 4, HTTPS, SSL/TLS, NO AUTH REMOTE EXPLOIT, JSSE\n\n**Products:** SSL/TLS","exploits":[{"source":"github-poc","url":"https://github.com/mpgn/BEAST-PoC","title":":muscle: Proof Of Concept of the BEAST attack against SSL/TLS CVE-2011-3389 :muscle:","date":"2015-03-28T10:28:16Z","stars":80}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["github-poc"],"topStars":80,"firstPOCDate":"2015-03-28T10:28:16Z"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.73327,"percentile":0.99432},"ssvc":{"available":false}}