CVE-2019-3738
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
Affected (42)
Products: Dell: Bsafe Cert J, Bsafe Crypto J, Bsafe Ssl J · Mcafee: Threat Intelligence Exchange Server · Oracle: Application Performance Management, Communications Network Integrity, Communications Unified Inventory Management, Database, Goldengate, Retail Assortment Planning, Retail Integration Bus, Retail Predictive Application Server, Retail Service Backbone, Retail Store Inventory Management, Retail Xstore Point Of Service, Storagetek Tape Analytics Sw Tool
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.2.4 | |
| Before 6.2.5 | |
| Up to 6.2.4.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.3.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 13.3.0.0 | |
| Version 7.3.2 | |
| Version 7.3.2 | |
| Version 12.1.0.2 | |
| Before 19.1.0.0.0.210420 | |
| Version 15.0.3.0 | |
| Version 14.1 | |
| Version 14.1.3.0 | |
| Version 14.1 | |
| Version 14.0.4 | |
| Version 15.0.3 | |
| Version 2.3 |
Related CWEs
CWE-325
Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
References (16)
Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.