Skip to main content
Apr 11, 2014

Apperian Heart Isn’t Bleeding

As you are likely well-aware, the Heartbleed OpenSSL vulnerability was announced earlier this week. It is one of the most severe zero-day exploits uncovered in recent years. Using this exploit, an attacker could gain access to a server’s private SSL key, allowing him to decrypt all information being sent to the server, including usernames, passwords, and other sensitive data. You can read more details about the vulnerability and its impact here: http://heartbleed.com/

Rest-Assured with Apperian’s Response

Upon publication of the vulnerability, our Operations staff audited all of our SSL end-points, and they found a few of our servers were running a vulnerable version of OpenSSL. Those servers were patched immediately to mitigate the risk of exposure. As of early Wednesday morning, Eastern Time, all of the servers with customer accounts were patched. As an additional precaution, we are now working with our Certificate Authority to re-issue all Apperian owned SSL certificates. There is no evidence that the Apperian servers were compromised or that any customer data was leaked.

However, due to the nature of this exploit and the length of time the vulnerability existed before being discovered, we recommend that customers reset their password, not just for Apperian, but with any website which contains sensitive data and has implemented the patch.

Apperian

More from the Blog
Feb 20, 2019

Part 4: App Security Should Be An Integral Part Of Your DevSecOps Process — Not An Afterthought

How Arxan can help streamline and optimize your DevSecOps process One of the most important factors to keep in mind when dep ...
Read more
Feb 13, 2019

Part 3: App Security Should Be An Integral Part Of Your DevSecOps Process — Not An Afterthought

Situations When DevSecOps Won’t Work Though DevSecOps is getting more popular by the day, and has many benefits to an organi ...
Read more
Feb 06, 2019

Part 2: App Security Should Be An Integral Part Of Your DevSecOps Process — Not an Afterthought

How to start implementing a DevSecOps process As you may have read in our
Read more