VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago

CVE-2014-3566

3.4 Low Out of RASP scope

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CWE-310CWE-329

Exploitation Status

Proof of concept only

A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment exploitation: none
  • Indexed PoC 6 indexed Published artifacts you can open, in GitHub PoC; first seen 2014-10-16.
  • EPSS 99.9% chance in 30 days A model prediction, not an observation. Higher than 99.9% of all scored CVEs.

5 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC :poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle: 267 2015-02-03
GitHub PoC mikesplain/CVE-2014-3566-poodle-cookbook 2 2014-10-16
GitHub PoC Auditoría de seguridad y análisis de vulnerabilidades (CVE-2014-3566 y CVE-2010-2333) en la infraestructura de red local y router residencial. 2026-05-30
GitHub PoC Vibe coded POC of exploitation of the POODLE CVE-2014-3566 2026-04-26
GitHub PoC Test code for poodle attack (CVE-2014-3566) 2024-11-14
GitHub PoC CloudPassage Halo policy for detecting vulnerability to CVE-2014-3566 (AKA POODLE) 2014-10-20

Waratek Defense Posture

Out of RASP scope

A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.

  • Protection none
  • Action not-needed none
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products

CVSS

3.4 LOW v3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 3.4 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N NVD Primary published
CVSS 3.1 3.4 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N CISA-ADP Secondary
CVSS 2.0 4.3 no band published AV:N/AC:M/Au:N/C:P/I:N/A:N NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update July 2017 CPU 2017-Q3 Oracle Database Server / DBMS_LDAP (11.2.0.4, 12.1.0.2)
Oracle Fusion Middleware / Core (OpenSSL) (7.4.0.0, 7.5.0.0, 7.5.1.0, 7.6.0.0, 7.6.1.0)
Oracle Critical Patch Update July 2016 CPU 2016-Q3 Oracle Sun Systems Products Suite / Firmware (Versions prior to 2.2.2)
Oracle Sun Systems Products Suite / Firmware (Versions prior to 2.2.2)
Oracle Critical Patch Update April 2016 CPU 2016-Q2 Oracle Sun Systems Products Suite / GlassFish Server (4.2)
Oracle Critical Patch Update July 2015 CPU 2015-Q3 Oracle Fusion Middleware / Oracle Tuxedo (SALT 10.3, SALT 11.1.1.2.2)
Oracle Critical Patch Update April 2015 CPU 2015-Q2 Oracle Sun Systems Products Suite / MGMT XML interface (3.1, 3.2)
Oracle Critical Patch Update January 2015 CPU 2015-Q1 Oracle Enterprise Manager Grid Control / Enterprise Manager Ops Center (11.1.3, 12.1.4)
Oracle Java SE / Java SE, Java SE Embedded, JRockit (Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4, JRockit 28.3.4)
Oracle Sun Systems Products Suite / Fujitsu M10-1, M10-4, M10-4S Servers (XCP prior to XCP 2240)
Oracle Sun Systems Products Suite / SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers (XCP prior to XCP 1119)
Oracle Virtualization / Oracle Secure Global Desktop (4.63, 4.71, 5.0, 5.1)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Database Server DBMS_LDAP 11.2.0.4, 12.1.0.2 11.2.0.4 · 12.1.0.2
Oracle Enterprise Manager Grid Control Enterprise Manager Ops Center 11.1.3, 12.1.4 11.1.3 · 12.1.4
Oracle Fusion Middleware Core (OpenSSL) 7.4.0.0, 7.5.0.0, 7.5.1.0, 7.6.0.0, 7.6.1.0 7.4.0.0 · 7.5.0.0 · 7.5.1.0 · 7.6.0.0 · 7.6.1.0
Oracle Fusion Middleware Oracle Tuxedo SALT 10.3, SALT 11.1.1.2.2 10.3 · 11.1.1.2.2
Oracle Java SE Java SE, Java SE Embedded, JRockit Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4, JRockit 28.3.4 5.0.75.0 · 6.0.85.0 · 7.0.71.0 · 7.0.72.0 · 8.0.6.0 · 8.0.25.0 · 27.8.4.0 · 28.3.4.0
Oracle Sun Systems Products Suite Firmware Versions prior to 2.2.2 2.2.2
Oracle Sun Systems Products Suite Fujitsu M10-1, M10-4, M10-4S Servers XCP prior to XCP 2240 2240
Oracle Sun Systems Products Suite GlassFish Server 4.2 4.2
Oracle Sun Systems Products Suite MGMT XML interface 3.1, 3.2 3.1 · 3.2
Oracle Sun Systems Products Suite SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers XCP prior to XCP 1119 1119
Oracle Virtualization Oracle Secure Global Desktop 4.63, 4.71, 5.0, 5.1 4.63 · 4.71 · 5.0 · 5.1

🖥️ Product CPEs & Version Ranges

20 product(s) over 146 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apple mac os x generic ≤ 10.10.1
nvd debian debian linux generic 7.0 · 8.0
nvd fedoraproject fedora generic 19 · 20 · 21
nvd ibm aix generic 5.3 · 6.1 · 7.1
nvd ibm vios generic 2.2.0.10 · 2.2.0.11 · 2.2.0.12 · 2.2.0.13 · 2.2.1.0 · 2.2.1.1 · 2.2.1.3 · 2.2.1.4 · 2.2.1.5 · 2.2.1.6 · 2.2.1.7 · 2.2.1.8 · 2.2.1.9 · 2.2.2.0 · 2.2.2.1 · 2.2.2.2 · 2.2.2.3 · 2.2.2.4 · 2.2.2.5 · 2.2.3.0 · 2.2.3.1 · 2.2.3.2 · 2.2.3.3 · 2.2.3.4
nvd mageia mageia generic 3.0 · 4.0
nvd netbsd netbsd generic 5.1 · 5.1.1 · 5.1.2 · 5.1.3 · 5.1.4 · 5.2 · 5.2.1 · 5.2.2 · 6.0 · 6.0:beta · 6.0.1 · 6.0.2 · 6.0.3 · 6.0.4 · 6.0.5 · 6.0.6 · 6.1 · 6.1.1 · 6.1.2 · 6.1.3 · 6.1.4 · 6.1.5
nvd novell suse linux enterprise desktop generic 9.0 · 10.0 · 11.0 · 12.0
nvd novell suse linux enterprise server generic 11.0:sp3 · 12.0
nvd novell suse linux enterprise software development kit generic 11.0:sp3 · 12.0
nvd openssl openssl generic 0.9.8 · 0.9.8a · 0.9.8b · 0.9.8c · 0.9.8d · 0.9.8e · 0.9.8f · 0.9.8g · 0.9.8h · 0.9.8i · 0.9.8j · 0.9.8k · 0.9.8l · 0.9.8m · 0.9.8m:beta1 · 0.9.8n · 0.9.8o · 0.9.8p · 0.9.8q · 0.9.8r · 0.9.8s · 0.9.8t · 0.9.8u · 0.9.8v · 0.9.8w · 0.9.8x · 0.9.8y · 0.9.8z · 0.9.8za · 0.9.8zb · 1.0.0 · 1.0.0:beta1 · 1.0.0:beta2 · 1.0.0:beta3 · 1.0.0:beta4 · 1.0.0:beta5 · 1.0.0a · 1.0.0b · 1.0.0c · 1.0.0d · 1.0.0e · 1.0.0f · 1.0.0g · 1.0.0h · 1.0.0i · 1.0.0j · 1.0.0k · 1.0.0l · 1.0.0m · 1.0.0n · 1.0.1 · 1.0.1:beta1 · 1.0.1:beta2 · 1.0.1:beta3 · 1.0.1a · 1.0.1b · 1.0.1c · 1.0.1d · 1.0.1e · 1.0.1f · 1.0.1g · 1.0.1h · 1.0.1i
nvd opensuse opensuse generic 12.3 · 13.1
nvd oracle database generic 11.2.0.4 · 12.1.0.2
nvd redhat enterprise linux generic 5
nvd redhat enterprise linux desktop generic 6.0 · 7.0
nvd redhat enterprise linux desktop supplementary generic 5.0 · 6.0
nvd redhat enterprise linux server generic 6.0 · 7.0
nvd redhat enterprise linux server supplementary generic 5.0 · 6.0 · 7.0
nvd redhat enterprise linux workstation generic 6.0 · 7.0
nvd redhat enterprise linux workstation supplementary generic 6.0 · 7.0

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** MGMT XML INTERFACE, PRINT SERVLET (ONLY IN 5.0 & 5.1), GATEWAY REVERSE PROXY, NETWORK ENCRYPTION, NO AUTH REMOTE EXPLOIT, CLIENT, LDAP, XCP FIRMWARE, HTTPS, GATEWAY JARP MODULE, FIRMWARE, CORE (OPENSSL), SSL/TLS, GLASSFISH SERVER, JSSE, WEB SERVER, SSL DAEMON (TTASSL), UPDATE PROVISIONING **Products:** SSL/TLS

References

URLTags
https://access.redhat.com/errata/RHSA-2015:0067 ADVISORY, RHSA-2015:0067
https://access.redhat.com/security/cve/CVE-2014-3566 REPORT, RHSA-2015:0067
https://access.redhat.com/errata/RHSA-2015:0068 ADVISORY, RHSA-2015:0068
https://access.redhat.com/errata/RHSA-2015:0069 ADVISORY, RHSA-2015:0069
https://access.redhat.com/errata/RHSA-2015:0080 ADVISORY, RHSA-2015:0080
https://access.redhat.com/errata/RHSA-2015:0085 ADVISORY, RHSA-2015:0085
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc Third Party Advisory
http://advisories.mageia.org/MGASA-2014-0416.html Third Party Advisory
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.asc Third Party Advisory
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html Third Party Advisory

Timeline

Published 2014-10-15 Last modified 2026-06-17
Published2014-10-15By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.