CVE-2014-3566The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CWE-310CWE-329
Proof of concept only
A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | :poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle: | 267 | 2015-02-03 |
| GitHub PoC | mikesplain/CVE-2014-3566-poodle-cookbook | 2 | 2014-10-16 |
| GitHub PoC | Auditoría de seguridad y análisis de vulnerabilidades (CVE-2014-3566 y CVE-2010-2333) en la infraestructura de red local y router residencial. | 2026-05-30 | |
| GitHub PoC | Vibe coded POC of exploitation of the POODLE CVE-2014-3566 | 2026-04-26 | |
| GitHub PoC | Test code for poodle attack (CVE-2014-3566) | 2024-11-14 | |
| GitHub PoC | CloudPassage Halo policy for detecting vulnerability to CVE-2014-3566 (AKA POODLE) | 2014-10-20 |
A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 3.4 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N |
NVD | Primary | published |
| CVSS 3.1 | 3.4 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N |
CISA-ADP | Secondary | |
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update July 2017 ↗ | CPU | 2017-Q3 | Oracle Database Server / DBMS_LDAP (11.2.0.4, 12.1.0.2) Oracle Fusion Middleware / Core (OpenSSL) (7.4.0.0, 7.5.0.0, 7.5.1.0, 7.6.0.0, 7.6.1.0) |
| Oracle Critical Patch Update July 2016 ↗ | CPU | 2016-Q3 | Oracle Sun Systems Products Suite / Firmware (Versions prior to 2.2.2) Oracle Sun Systems Products Suite / Firmware (Versions prior to 2.2.2) |
| Oracle Critical Patch Update April 2016 ↗ | CPU | 2016-Q2 | Oracle Sun Systems Products Suite / GlassFish Server (4.2) |
| Oracle Critical Patch Update July 2015 ↗ | CPU | 2015-Q3 | Oracle Fusion Middleware / Oracle Tuxedo (SALT 10.3, SALT 11.1.1.2.2) |
| Oracle Critical Patch Update April 2015 ↗ | CPU | 2015-Q2 | Oracle Sun Systems Products Suite / MGMT XML interface (3.1, 3.2) |
| Oracle Critical Patch Update January 2015 ↗ | CPU | 2015-Q1 | Oracle Enterprise Manager Grid Control / Enterprise Manager Ops Center (11.1.3, 12.1.4) Oracle Java SE / Java SE, Java SE Embedded, JRockit (Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4, JRockit 28.3.4) Oracle Sun Systems Products Suite / Fujitsu M10-1, M10-4, M10-4S Servers (XCP prior to XCP 2240) Oracle Sun Systems Products Suite / SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers (XCP prior to XCP 1119) Oracle Virtualization / Oracle Secure Global Desktop (4.63, 4.71, 5.0, 5.1) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Database Server | DBMS_LDAP | 11.2.0.4, 12.1.0.2 | 11.2.0.4 · 12.1.0.2 |
| Oracle Enterprise Manager Grid Control | Enterprise Manager Ops Center | 11.1.3, 12.1.4 | 11.1.3 · 12.1.4 |
| Oracle Fusion Middleware | Core (OpenSSL) | 7.4.0.0, 7.5.0.0, 7.5.1.0, 7.6.0.0, 7.6.1.0 | 7.4.0.0 · 7.5.0.0 · 7.5.1.0 · 7.6.0.0 · 7.6.1.0 |
| Oracle Fusion Middleware | Oracle Tuxedo | SALT 10.3, SALT 11.1.1.2.2 | 10.3 · 11.1.1.2.2 |
| Oracle Java SE | Java SE, Java SE Embedded, JRockit | Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4, JRockit 28.3.4 | 5.0.75.0 · 6.0.85.0 · 7.0.71.0 · 7.0.72.0 · 8.0.6.0 · 8.0.25.0 · 27.8.4.0 · 28.3.4.0 |
| Oracle Sun Systems Products Suite | Firmware | Versions prior to 2.2.2 | 2.2.2 |
| Oracle Sun Systems Products Suite | Fujitsu M10-1, M10-4, M10-4S Servers | XCP prior to XCP 2240 | 2240 |
| Oracle Sun Systems Products Suite | GlassFish Server | 4.2 | 4.2 |
| Oracle Sun Systems Products Suite | MGMT XML interface | 3.1, 3.2 | 3.1 · 3.2 |
| Oracle Sun Systems Products Suite | SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers | XCP prior to XCP 1119 | 1119 |
| Oracle Virtualization | Oracle Secure Global Desktop | 4.63, 4.71, 5.0, 5.1 | 4.63 · 4.71 · 5.0 · 5.1 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apple | mac os x | generic | ≤ 10.10.1 |
| nvd | debian | debian linux | generic | 7.0 · 8.0 |
| nvd | fedoraproject | fedora | generic | 19 · 20 · 21 |
| nvd | ibm | aix | generic | 5.3 · 6.1 · 7.1 |
| nvd | ibm | vios | generic | 2.2.0.10 · 2.2.0.11 · 2.2.0.12 · 2.2.0.13 · 2.2.1.0 · 2.2.1.1 · 2.2.1.3 · 2.2.1.4 · 2.2.1.5 · 2.2.1.6 · 2.2.1.7 · 2.2.1.8 · 2.2.1.9 · 2.2.2.0 · 2.2.2.1 · 2.2.2.2 · 2.2.2.3 · 2.2.2.4 · 2.2.2.5 · 2.2.3.0 · 2.2.3.1 · 2.2.3.2 · 2.2.3.3 · 2.2.3.4 |
| nvd | mageia | mageia | generic | 3.0 · 4.0 |
| nvd | netbsd | netbsd | generic | 5.1 · 5.1.1 · 5.1.2 · 5.1.3 · 5.1.4 · 5.2 · 5.2.1 · 5.2.2 · 6.0 · 6.0:beta · 6.0.1 · 6.0.2 · 6.0.3 · 6.0.4 · 6.0.5 · 6.0.6 · 6.1 · 6.1.1 · 6.1.2 · 6.1.3 · 6.1.4 · 6.1.5 |
| nvd | novell | suse linux enterprise desktop | generic | 9.0 · 10.0 · 11.0 · 12.0 |
| nvd | novell | suse linux enterprise server | generic | 11.0:sp3 · 12.0 |
| nvd | novell | suse linux enterprise software development kit | generic | 11.0:sp3 · 12.0 |
| nvd | openssl | openssl | generic | 0.9.8 · 0.9.8a · 0.9.8b · 0.9.8c · 0.9.8d · 0.9.8e · 0.9.8f · 0.9.8g · 0.9.8h · 0.9.8i · 0.9.8j · 0.9.8k · 0.9.8l · 0.9.8m · 0.9.8m:beta1 · 0.9.8n · 0.9.8o · 0.9.8p · 0.9.8q · 0.9.8r · 0.9.8s · 0.9.8t · 0.9.8u · 0.9.8v · 0.9.8w · 0.9.8x · 0.9.8y · 0.9.8z · 0.9.8za · 0.9.8zb · 1.0.0 · 1.0.0:beta1 · 1.0.0:beta2 · 1.0.0:beta3 · 1.0.0:beta4 · 1.0.0:beta5 · 1.0.0a · 1.0.0b · 1.0.0c · 1.0.0d · 1.0.0e · 1.0.0f · 1.0.0g · 1.0.0h · 1.0.0i · 1.0.0j · 1.0.0k · 1.0.0l · 1.0.0m · 1.0.0n · 1.0.1 · 1.0.1:beta1 · 1.0.1:beta2 · 1.0.1:beta3 · 1.0.1a · 1.0.1b · 1.0.1c · 1.0.1d · 1.0.1e · 1.0.1f · 1.0.1g · 1.0.1h · 1.0.1i |
| nvd | opensuse | opensuse | generic | 12.3 · 13.1 |
| nvd | oracle | database | generic | 11.2.0.4 · 12.1.0.2 |
| nvd | redhat | enterprise linux | generic | 5 |
| nvd | redhat | enterprise linux desktop | generic | 6.0 · 7.0 |
| nvd | redhat | enterprise linux desktop supplementary | generic | 5.0 · 6.0 |
| nvd | redhat | enterprise linux server | generic | 6.0 · 7.0 |
| nvd | redhat | enterprise linux server supplementary | generic | 5.0 · 6.0 · 7.0 |
| nvd | redhat | enterprise linux workstation | generic | 6.0 · 7.0 |
| nvd | redhat | enterprise linux workstation supplementary | generic | 6.0 · 7.0 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** MGMT XML INTERFACE, PRINT SERVLET (ONLY IN 5.0 & 5.1), GATEWAY REVERSE PROXY, NETWORK ENCRYPTION, NO AUTH REMOTE EXPLOIT, CLIENT, LDAP, XCP FIRMWARE, HTTPS, GATEWAY JARP MODULE, FIRMWARE, CORE (OPENSSL), SSL/TLS, GLASSFISH SERVER, JSSE, WEB SERVER, SSL DAEMON (TTASSL), UPDATE PROVISIONING **Products:** SSL/TLS
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2015:0067 | ADVISORY, RHSA-2015:0067 |
| https://access.redhat.com/security/cve/CVE-2014-3566 | REPORT, RHSA-2015:0067 |
| https://access.redhat.com/errata/RHSA-2015:0068 | ADVISORY, RHSA-2015:0068 |
| https://access.redhat.com/errata/RHSA-2015:0069 | ADVISORY, RHSA-2015:0069 |
| https://access.redhat.com/errata/RHSA-2015:0080 | ADVISORY, RHSA-2015:0080 |
| https://access.redhat.com/errata/RHSA-2015:0085 | ADVISORY, RHSA-2015:0085 |
| ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc | Third Party Advisory |
| http://advisories.mageia.org/MGASA-2014-0416.html | Third Party Advisory |
| http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.asc | Third Party Advisory |
| http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html | Third Party Advisory |
| Published | 2014-10-15 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |