In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cryptographic Issues vulnerabilities in an interactive lesson.
Start learningUpgrade RHEL:7 openssl-static to version 1:1.0.1e-51.el7_2.4 or higher.
This issue was patched in RHSA-2016:0301.
Note: Versions mentioned in the description apply only to the upstream openssl-static package and not the openssl-static package as distributed by RHEL.
See How to fix? for RHEL:7 relevant fixed versions and status.
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.