KB Article #181361

OpenSSL Raccoon CVE CVE-2020-1968

Problem

-- Is API Gateway vulnerable to OpenSSL vulnerability CVE-2020-1968 a.k.a. "Raccoon"?

https://www.openssl.org/news/secadv/20200909.txt


Resolution

* Starting with March 2020 release, API Gateway delivers OpenSSL 1.1.1 and consequently is not vulnerable.

* Previous releases may be vulnerable but are end of support and will not be fixed.