Getting Data In

Found a SSLv3 "POODLE" vulnerability on Universal Forwarder 6.4.2. How to resolve this?

season88481
Contributor

We just found SSLv3 "POODLE" vulnerability alerts from our IPS system. And our Splunk Universal Forwarder is in 6.4.2.

I thought the SSLv3 POODLE issue only appear at Splunk version earlier than 6.3?

Should I use the same workaround mention here?
https://answers.splunk.com/answers/176970/is-it-possible-to-disable-ssl-v3-on-the-universal.html

Many thanks in advance.

0 Karma
1 Solution

gokadroid
Motivator

Can you please have a look at this blog which talks about fixing the poodle vulnerability on Splunk:

http://blogs.splunk.com/2014/10/22/mitigating-the-poodle-attack-in-splunk/

View solution in original post

aaraneta_splunk
Splunk Employee
Splunk Employee

@season88481 - Did the Splunk blog post referenced by gokadroid below help answer to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

gokadroid
Motivator

Can you please have a look at this blog which talks about fixing the poodle vulnerability on Splunk:

http://blogs.splunk.com/2014/10/22/mitigating-the-poodle-attack-in-splunk/

season88481
Contributor

So we are not using SSL forwarding between uf and HWF.

The only SSL communication I can think of is the REST connection of 8089. However, since we are not doing any command line or REST request to the uf. So I will try disabling the management port by deploying a server.conf

[httpServer]
disableDefaultPort = true

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...