CVE-2018-1000180
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Affected (29)
Products: Bouncycastle: Bc Java, Fips Java Api · Debian: Debian Linux · Oracle: Api Gateway, Business Process Management Suite, Business Transaction Management, Communications Application Session Controller, Communications Converged Application Server, Communications Webrtc Session Controller, Enterprise Repository, Managed File Transfer, Peoplesoft Enterprise Peopletools, Retail Convenience And Fuel Pos Software, Retail Xstore Point Of Service, Soa Suite, Webcenter Portal, Weblogic Server · +2 more
Show all products
Bouncycastle: Bc Java, Fips Java Api · Debian: Debian Linux · Oracle: Api Gateway, Business Process Management Suite, Business Transaction Management, Communications Application Session Controller, Communications Converged Application Server, Communications Webrtc Session Controller, Enterprise Repository, Managed File Transfer, Peoplesoft Enterprise Peopletools, Retail Convenience And Fuel Pos Software, Retail Xstore Point Of Service, Soa Suite, Webcenter Portal, Weblogic Server · Netapp: Oncommand Workflow Automation · Redhat: Virtualization, Jboss Enterprise Application Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.54 to 1.59 | |
| Up to 1.0.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.4.0 | |
| Version 11.1.1.9.0 | |
| Version 12.1.0 | |
| Version 3.7.1 | |
| Before 7.0.0.1 | |
| Before 7.2 | |
| Version 12.1.3.0.0 | |
| Version 12.1.3.0.0 | |
| Version 8.55 | |
| Version 2.8.1 | |
| Version 7.0 | |
| Version 12.1.3.0.0 | |
| Version 11.1.1.9.0 | |
| Version 12.1.3.0.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.2 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
References (42)
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.