Get access to immediate incident response assistance.
Trustwave recommends that SSLv2 and SSLv3 should be disabled on all web servers that provide service for the named products (such as SQM/End user spam and quarantine management, remote consoles, and reporting consoles), if the sites are secured with HTTPS. These protocol versions are older and have known vulnerabilities. For example, CVE-2014-3566 ("Poodle") is a vulnerability in the SSLv3 protocol that potentially allows an attacker to view the plain text of encrypted material.
For technical details of how to disable SSLv2 and SSLv3 on Windows servers, refer to Microsoft documentation.
To contact Trustwave about this article or to request support:
This is a bot-free zone. Please check the box to let us know you're human.
Download Now
Read complimentary reports and insightful stories in the Trustwave Resource Center
One of our sales specialists will be in touch shortly.