← Back

CVE-2018-1000613

nvd nist
Published: Jul 9, 2018Modified: May 12, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

Affected (47)

Show all products
1 product
Bc Java
1 product
Oncommand Workflow Automation
1 product
Leap
21 products
Api Gateway
Banking Platform
Business Process Management Suite
Business Transaction Management
Communications Convergence
Data Integrator
Enterprise Manager Base Platform
Enterprise Repository
Managed File Transfer
Peoplesoft Enterprise Peopletools
Retail Xstore Point Of Service
Soa Suite
Webcenter Portal
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.58 to 1.60
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
44 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.1.2.4.0
Oracle
Version 2.6.0
Version 2.6.1
Version 2.6.2
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.1.0
Oracle
Version 3.7.1
Version 3.8.0
Oracle
Before 7.0.0.1
Version 7.0.0.1
Version 3.0.2
Oracle
Version 8.0.0
Version 8.1
Version 8.2.1
Version 8.2
Oracle
Before 7.2
Version 7.2
Version 12.2.1.3.0
Oracle
Version 12.1.0.5.0
Version 13.2.0.0
Version 13.3.0.0
Oracle
Version 13.2.0.0
Version 13.3.0.0
Oracle
Version 11.1.1.7.0
Version 12.1.3.0.0
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
Version 8.55
Version 8.56
Version 8.57
Version 2.8.1
Oracle
Version 7.0
Version 7.1
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
Version 1.12.0.3
Version 2.3.0.0
Version 2.3.0.1
Version 2.3.0.2
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.3

References (22)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.