Security Alert 50814: DES/3DES Security Cipher Vulnerability

This document describes the security alert for an AppDynamics product.

Affected Software

ProductComponentVersionExploitabilitySeverity
.NET AgentAppDynamics DotNet AgentAllNoHigh

This update is known to impact .NET APM Agents running on Windows 2003 Server where the latest security ciphers have not been installed. .NET Agents running on Windows 2008/2012, as well as all Java agents, are not affected by this update.

Impact

.NET APM Agents running on Windows 2003 Server will begin to throw the following error while attempting to communicate with the SaaS controller:

System.Net.WebException: The underlying connection was closed: An unexpected error occurred on a send. ---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host.

Disclaimer

The information provided in this security advisory is provided "as is" without warranty of any kind. AppDynamics disclaims all representations or warranties, either express, implied, statutory, or otherwise with respect thereto, including the warranties of merchantability and fitness for a particular purpose. In no event shall AppDynamics, its affiliates, or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits, or special damages, even if the other party has been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply to you.

Revision History

1.0 - 2/9/2017 Initial Revision