• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM And ISVs Fight POODLE Vulnerability In SSL 3.0

    November 10, 2014 Alex Woodie

    IBM is among the software vendors working to issue patches to address the newly discovered POODLE attack, which exploits a vulnerability in SSL 3.0 to overcome encryption and view actual content. IBM has issued a patch for Domino and is currently working on a patch for WebSphere Application Server for IBM i. IBM i ISVs are also responding to the new threat.

    The POODLE attack, which stands for “Padding Oracle On Downgraded Legacy Encryption,” was first described in September by a group of Google researchers. If successfully executed, the POODLE attack requires a perpetrator to make just 256 SSL 3.0 requests to reveal one byte of encrypted messages.

    While the POODLE attack is not considered as serious as the Heartbleed or Shellshock vulnerabilities that rocked the cybersecurity world earlier this year, it is nevertheless a critical problem because it basically renders SSL 3.0 worthless from a security point of view. The problem is, many Web applications revert back to SSL 3.0 as the default. While TLS 1.x is more secure than SSL 3.0, the interoperability of SSL 3.0 makes it a popular choice among developers. (TLS is short for Transport Layer Security and is the new name of SSL to avoid a possible trademark issue with Netscape, the original commercializer of the Web browser. TLS 1.0 is equivalent to SSL 3.1.)

    IBM addressed the POODLE problem in its various products. It issued a security bulletin for WebSphere Application Server, which uses SSL 3.0 by default. The associated patches disable SSL 3.0. It also issued a issued issued a security bulletin for the Apache-based HTTP Server, where SSL 3.0 is enabled by default. IBM recommends disabling SSL 3.0 in all instances of the Apache Web server, including those on IBM i, z/OS, AIX, Linux, Windows, and Solaris.

    All versions of WebSphere are also vulnerable, including WebSphere Application Server for IBM i. IBM hasn’t yet delivered an update for this product or the IBM Developer Kit for Java, which is where the underlying encryption protocol changes need to be made. IBM says to check the Java on IBM i webpage for news of the patch.

    On November 3, IBM issued an interim fix for Domino, which is also susceptible to the POODLE attack. The Domino fix disables SSL 3.0 and adds support for TLS 1.0. It supports all platforms, IBM says, including “iSeries running System SSL.” IBM Connections, the business social media software, is also vulnerable, since it uses the HTTP Server as well. You can read more about this at the IBM Connections website.

    The new POODLE vulnerability is nothing to toy around with.

    Other IBM i applications are also affected by this vulnerability. Third-party software vendors have been free to use IBM’s System SSL facility (which supports SSL as well as TLS) to encrypt communications on the platforms. Most, if not all, file transfer and 5250 emulators have used SSL at some point. However, most vendors have since moved toward using the Secure Shell (SSH) method of communication as a replacement for SSL.

    Linoma Software addressed the POODLE vulnerability and its impact by issuing a patch for its GoAnywhere managed file transfer (MFT) products. The patch will either disable SSL 3.0, which the company recommends, while acknowledging that it may disrupt communications. “SSLv3 encryption,” the company writes on its website, “while significantly dated, is still widely used throughout the world.” The patch will also just disable the CBC cipher algorithms that are the heart of the problems in SSL 3.0.

    At the very least, IBM i shops will want to disable any and all instances of SSL 3.0 running on their systems. Companies that have upgraded to the latest release of the OS, IBM i 7.2, will get this automatically. With IBM i 7.2, IBM supports TLS 1.1 and TLS 1.1 by default, and disables SSL 3.0 by default.

    IBM i added support for TLS 1.1 and TLS 1.2 in early 2013 with IBM i 7.1 Technology Refresh 6, when it was already clear that SSL 3.0 was on its way out and TLS would soon be a requirement. TLS 1.1 has been available on the platform since OS/400 V4R5 was released in the early days of the millennium.

    Back in 2013, IBM i chief architect Steve Will explained that IBM was aware of changes taking place with the SSL/TLS protocols, especially SSL 3.0, which has been in use for well over a decade. “Many institutions are saying, if I’m going to allow SSL, I want it to have the stronger hashing technique in order to be able to protect my data better when it’s flowing across an SSL encrypted line,” he told IT Jungle at the time.

    RELATED STORIES

    Heartbleed Exposes The Vulnerability Of An IBM i Mentality

    IBM Patches Heartbleed Vulnerability in Power Systems Firmware

    Heartbleed Postmortem: Time to Rethink Open Source Security?

    Heartbleed, OpenSSL, and IBM i: What You Need to Know



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    HelpSystems Bolsters Automation Tool with Database Triggers TR8 DB2 For i Enhancements, Part 1

    Leave a Reply Cancel reply

Volume 24, Number 38 -- November 10, 2014
THIS ISSUE SPONSORED BY:

ARCAD Software
Infinite Corporation
ASNA
Computer Keyes
Shield Advanced Solutions

Table of Contents

  • First Pass On Power8 Enterprise Performance
  • Dispatches From The IBM i MSP Frontier
  • IBM And ISVs Fight POODLE Vulnerability In SSL 3.0
  • Mad Dog 21/21: Pandora’s Pithos
  • College RPG Needs A Technology Refresh
  • IBM i App Dev Progress: It Doesn’t Just Happen By Itself
  • SaaS Helps Lift Hospitality Software Maker Agilysys
  • Cloud Spending Dominated By SaaS In The Years Ahead
  • Unlocking The Power8 Features With IBM i
  • IBM Builds Infrastructure Resource Site

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle