CVE-2019-1559 Details
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openssl openssl | >= 1.0.2, < 1.0.2r |
CPE
Remediation
| |
| canonical ubuntu linux | 16.04 18.04 18.10 |
CPE
Remediation
| |
| debian debian linux | 8.0 9.0 |
CPE
Remediation
| |
| netapp active iq unified manager | >= 7.3 >= 9.5 |
CPE
Remediation
| |
| netapp altavault | All versions |
CPE
Remediation
| |
| netapp cloud backup | All versions |
CPE
Remediation
| |
| netapp clustered data ontap antivirus connector | All versions |
CPE
Remediation
| |
| netapp element software | All versions |
CPE
Remediation
| |
| netapp hci management node | All versions |
CPE
Remediation
| |
| netapp hyper converged infrastructure | All versions |
CPE
Remediation
| |
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| netapp oncommand unified manager | All versions |
CPE
Remediation
| |
| netapp oncommand unified manager core package | All versions |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp ontap select deploy | All versions |
CPE
Remediation
| |
| netapp ontap select deploy administration utility | All versions |
CPE
Remediation
| |
| netapp santricity smi-s provider | All versions |
CPE
Remediation
| |
| netapp service processor | All versions |
CPE
Remediation
| |
| netapp smi-s provider | All versions |
CPE
Remediation
| |
| netapp snapcenter | All versions |
CPE
Remediation
| |
| netapp snapdrive | All versions |
CPE
Remediation
| |
| netapp snapprotect | All versions |
CPE
Remediation
| |
| netapp solidfire | All versions |
CPE
Remediation
| |
| netapp steelstore cloud integrated storage | All versions |
CPE
Remediation
| |
| netapp storage automation store | All versions |
CPE
Remediation
| |
| netapp storagegrid | >= 9.0.0, <= 9.0.4 |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| f5 big-ip access policy manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip advanced firewall manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip analytics | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip application acceleration manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip application security manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip domain name system | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip edge gateway | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip fraud protection service | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip global traffic manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip link controller | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip local traffic manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip policy enforcement manager | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-ip webaccelerator | >= 12.1.0, <= 12.1.5 >= 13.0.0, <= 13.1.3 >= 14.0.0, <= 14.1.2 >= 15.0.0, <= 15.1.0 |
CPE
Remediation
| |
| f5 big-iq centralized management | >= 6.0.0, <= 6.1.0 >= 7.0.0, <= 7.1.0 |
CPE
Remediation
| |
| f5 traffix signaling delivery controller | >= 5.0.0, <= 5.1.0 4.4.0 |
CPE
Remediation
| |
| tenable nessus | <= 8.2.3 |
CPE
Remediation
| |
| opensuse leap | 15.0 15.1 42.3 |
CPE
Remediation
| |
| netapp cn1610 firmware | All versions |
CPE
Remediation
| |
| netapp cn1610 | All versions |
CPE
Remediation
| |
| netapp a320 firmware | All versions |
CPE
Remediation
| |
| netapp a320 | All versions |
CPE
Remediation
| |
| netapp c190 firmware | All versions |
CPE
Remediation
| |
| netapp c190 | All versions |
CPE
Remediation
| |
| netapp a220 firmware | All versions |
CPE
Remediation
| |
| netapp a220 | All versions |
CPE
Remediation
| |
| netapp fas2720 firmware | All versions |
CPE
Remediation
| |
| netapp fas2720 | All versions |
CPE
Remediation
| |
| netapp fas2750 firmware | All versions |
CPE
Remediation
| |
| netapp fas2750 | All versions |
CPE
Remediation
| |
| netapp a800 firmware | All versions |
CPE
Remediation
| |
| netapp a800 | All versions |
CPE
Remediation
| |
| fedoraproject fedora | 29 30 31 |
CPE
Remediation
| |
| mcafee agent | >= 5.6.0, <= 5.6.4 |
CPE
Remediation
| |
| mcafee data exchange layer | >= 4.0.0, < 6.0.0 |
CPE
Remediation
| |
| mcafee threat intelligence exchange server | >= 2.0.0, < 3.0.0 |
CPE
Remediation
| |
| mcafee web gateway | >= 7.0.0, < 9.0.0 |
CPE
Remediation
| |
| redhat jboss enterprise web server | 5.0.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 |
CPE
Remediation
| |
| redhat virtualization | 4.0 |
CPE
Remediation
| |
| redhat virtualization host | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 7.0 |
CPE
Remediation
| |
| oracle api gateway | 11.1.2.4.0 |
CPE
Remediation
| |
| oracle business intelligence | 11.1.1.9.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications diameter signaling router | 8.0.0 8.1 8.2 8.3 8.4 |
CPE
Remediation
| |
| oracle communications performance intelligence center | 10.4.0.2 |
CPE
Remediation
| |
| oracle communications session border controller | 7.4 8.0.0 8.1.0 8.2 8.3 |
CPE
Remediation
| |
| oracle communications session router | 7.4 8.0 8.1 8.2 8.3 |
CPE
Remediation
| |
| oracle communications unified session manager | 7.3.5 8.2.5 |
CPE
Remediation
| |
| oracle endeca server | 7.7.0 |
CPE
Remediation
| |
| oracle enterprise manager base platform | 12.1.0.5.0 13.2.0.0.0 13.3.0.0.0 |
CPE
Remediation
| |
| oracle enterprise manager ops center | 12.3.3 12.4.0 |
CPE
Remediation
| |
| oracle jd edwards enterpriseone tools | 9.2 |
CPE
Remediation
| |
| oracle jd edwards world security | a9.3 a9.3.1 a9.4 |
CPE
Remediation
| |
| oracle mysql | >= 5.6.0, <= 5.6.43 >= 5.7.0, <= 5.7.25 >= 8.0.0, <= 8.0.15 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 4.0.8 >= 8.0.0, <= 8.0.14 |
CPE
Remediation
| |
| oracle mysql workbench | <= 8.0.16 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.55 8.56 8.57 |
CPE
Remediation
| |
| oracle secure global desktop | 5.4 |
CPE
Remediation
| |
| oracle services tools bundle | 19.2 |
CPE
Remediation
| |
| paloaltonetworks pan-os | >= 7.1.0, < 7.1.15 >= 8.0.0, < 8.0.20 >= 8.1.0, < 8.1.8 >= 9.0.0, < 9.0.2 |
CPE
Remediation
| |
| nodejs node.js | >= 6.0.0, <= 6.8.1 >= 6.9.0, < 6.17.0 >= 8.0.0, <= 8.8.1 >= 8.9.0, < 8.15.1 |
CPE
Remediation
| |
Change History
44 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Aug 19, 2022 | Reanalysis | [email protected] |
| Mar 24, 2022 | Modified Analysis | [email protected] |
| Jan 20, 2021 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Jul 22, 2020 | CVE Modified | [email protected] |
| Jan 15, 2020 | CVE Modified | [email protected] |
| Nov 20, 2019 | CVE Modified | [email protected] |
| Oct 16, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 26, 2019 | CVE Modified | [email protected] |
| Sep 25, 2019 | CVE Modified | [email protected] |
| Sep 21, 2019 | CVE Modified | [email protected] |
| Aug 13, 2019 | CVE Modified | [email protected] |
| Aug 12, 2019 | CVE Modified | [email protected] |
| Aug 6, 2019 | CVE Modified | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| Jun 27, 2019 | CVE Modified | [email protected] |
| May 22, 2019 | CVE Modified | [email protected] |
| May 15, 2019 | CVE Modified | [email protected] |
| May 15, 2019 | CVE Modified | [email protected] |
| Apr 25, 2019 | Modified Analysis | [email protected] |
| Apr 23, 2019 | CVE Modified | [email protected] |
| Apr 23, 2019 | CVE Modified | [email protected] |
| Apr 8, 2019 | CVE Modified | [email protected] |
| Apr 2, 2019 | CVE Modified | [email protected] |
| Mar 29, 2019 | Modified Analysis | [email protected] |
| Mar 28, 2019 | CVE Modified | [email protected] |
| Mar 27, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Mar 18, 2019 | Modified Analysis | [email protected] |
| Mar 14, 2019 | CVE Modified | [email protected] |
| Mar 8, 2019 | CVE Modified | [email protected] |
| Mar 4, 2019 | Modified Analysis | [email protected] |
| Mar 4, 2019 | CVE Modified | [email protected] |
| Mar 2, 2019 | CVE Modified | [email protected] |
| Mar 1, 2019 | Modified Analysis | [email protected] |
| Mar 1, 2019 | CVE Modified | [email protected] |
| Feb 28, 2019 | Reanalysis | [email protected] |
| Feb 28, 2019 | Initial Analysis | [email protected] |
| Feb 28, 2019 | CVE Modified | [email protected] |