Skip to Main Content

Enterprise Manager

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

SSL Medium Strength Cipher Suites Supported (SWEET32)

Berfin GürzJan 26 2023 — edited Jan 27 2023

Hi guys,

I have a problem with vulnerability. And this vulnerability comes from Oracle Enterprise Management hosts. Information like this:
PORT : 7301
PROTOCOL : TCP
PLUGINID : 42873
PLUGGINIDDESC : SSL Medium Strength Cipher Suites Supported (SWEET32)
CVSS : 5.0
DETAILS: The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite. Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.

I don't see any documentation about that. How can I close the vulnerability?

Thanks.

Comments
Post Details
Added on Jan 26 2023
0 comments
1,263 views