Poodle Bite, Sandworm, .NET MS14-057, and other OpenSSL Vulnerabilities and Impact in RSA products
Originally Published: 2017-02-10
Article Number
Applies To
CVE Identifier(s)
Article Summary
Issue
- SSL v3 CBC Poodle Bite (CVE-2014-3566),
- Windows Sandworm (CVE-2014-4114),
- Microsoft .Net (MS14-057) and multiple OpenSSL Vulnerabilities (OpenSSL)
References
- Sandworm CVE-2014-4114
- Poodle CVE-2014-3566
- OpenSSL
- SRTP Memory Leak CVE-2014-3513
- Session Ticket Memory Leak CVE-2014-3567
- SSL 3.0 Fallback protection (Poodle in OpenSSL implementation) CVE-2014-3566
- Build option no-ssl3 is incomplete CVE-2014-3568
- Microsoft Security Bulletin MS14-057 (Vulnerabilities in .NET Framework Could Allow Remote Code Execution) comprised of the following:
- .NET ClickOnce Elevation of Privilege Vulnerability (CVE-2014-4073)
- .NET Framework Remote Code Execution Vulnerability (CVE-2014-4121)
- .NET ASLR Vulnerability (CVE-2014-4122)
Resolution
Sandworm information
RSA enVision is impacted by Sandworm and remediation is currently being investigated.Microsoft .Net (MS14-057) information
Customers utilizing the RSA Archer Platform are urged to update the .NET framework to the latest available security updates from Microsoft.This table will be updated as additional information becomes available.
| RSA Product Name | Versions | Poodle Bite Impact | OpenSSL Impact | Additional Information |
| 3D Secure | ALL Supported | Remediated | N/A | |
| Access Manager | ALL Supported | Not Impacted | Not Impacted | |
| Adaptive Authentication Hosted | ALL Supported | Remediated | SSLv3 Disabled on 11/16 | |
| Adaptive Authentication On Prem | ALL Supported | Not Impacted | ||
| Archer Hosted | N/A | Remediated | N/A | Does not use OpenSSL |
| Archer Platform | ALL Supported | Not Impacted | N/A | Does not use OpenSSL |
| Archer SecOps | ALL Supported | Investigating | ||
| Archer Vulnerability & Risk Manager (VRM) | ALL Supported | Investigating | ||
| Authentication Manager Software Platform | 6.1 | Not Impacted | Not Impacted | |
| Authentication Manager Software Platform | 7.1 | Impacted - Remediation under investigation | Not Impacted | |
| Authentication Manager Appliance | 3.0 | Impacted - Remediation under investigation | Not Impacted | |
| Authentication Manager Appliance | 8.0, 8.1, 8.2 | Not Impacted | Not Impacted | Includes Web Tier |
| Authentication Manager Express | 1.0 | Impacted - Remediation under investigation | Not Impacted | |
| BSAFE | ALL Supported | Not Impacted | Not Impacted | |
| Data Loss Protection | ALL Supported | Not Impacted | Not Impacted | |
| Data Protection Manager | ALL Supported | Not Impacted | Not Impacted | |
| Digital Certificate Server | ALL Supported | Not Impacted | Not Impacted | |
| ECAT | ALL Supported | Remediated | Not Impacted | See Solution ID 28901 |
| enVision | ALL Supported | Impacted - Remediation planned for future release | Not Impacted | |
| Federated Identity Manager | ALL Supported | Not Impacted | ||
| FraudAction | ALL Supported | Not Impacted | ||
| IMG (Aveksa) Hosted | ALL Supported | Not Impacted | Not Impacted | |
| IMG (Aveksa) On-Prem Platform | ALL Supported | Not Impacted | Not Impacted | |
| IMG (Aveksa) Appliance | ALL Supported | Remediated | See solution ID 29019 | |
| IMG (Aveksa) StealthAudit | ALL Supported | Investigating | ||
| Netwitness | 9.7.x, 9.8.x | Remediated | Resolved with Q3 Security Update EL5 platform must upgrade to EL6 | |
| Netwitness Informer | 1.x | Impacted - Remediation under investigation | ||
| RSA Live Infrastructure | ALL Supported | Remediated | ||
| SecurID 700 Hardware Token | ALL Supported | N/A | N/A | |
| SecurID 800 Hardware Token | ALL Supported | N/A | N/A | |
| SecurID Agent for PAM | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Agent for UNIX | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Agent for Web | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Agent for Windows | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Authentication Engine | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Authentication SDK | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token Converter | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token for Android | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token for Blackberry | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token for Desktop | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token for iPhone | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token for Windows Mobile | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token Toolbar | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Software Token Web SDK | ALL Supported | Not Impacted | Not Impacted | |
| SecurID Transaction SigningSDK | ALL Supported | Not Impacted | Not Impacted | |
| Security Analytics Platform Physical and Virtual Appliances | 10.0.x-10.4.x | Remediated | Resolved with Q3 Security Update | |
| Security Analytics Malware Analytics | 10.0.x-10.4.x | Remediated | Resolved with Q3 Security Update | |
| Security Analytics Malware Cloud | N/A | Remediated | Not Impacted | |
| Security Analytics (Windows Legacy Collector) | 10.0.x-10.4.x | Investigating | ||
| Security Analytics Warehouse (DCA Pivotal) | Remediated | Pivotal patch available | ||
| Security Analytics Warehouse (MapR) | Investigating | |||
| Spectrum | 1.x | Impacted - Remediation under investigation | ||
| Web Threat Detection (Silvertail) | ALL Supported | Remediated |
Disclaimer
Related Articles
"java.lang.RuntimeException: java.lang.OutOfMemoryError: Java heap space" errors occur frequently in versions 6.x of RSA I… 61Number of Views Does S/MIME-C 2.1.x support 2048-bit RSA keys? 13Number of Views Poodle Bite Sandworm .Net MS14-057 OpenSSL Vulnerabilities and Impact in RSA products 4.79KNumber of Views 'javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path' error when testing a RESTful W… 325Number of Views AFX Connector test capability fails with java.lang.NoClassDefFoundError in RSA Governance & Lifecycle 264Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?