← Back

CVE-2020-28052

nvd nist
Published: Dec 18, 2020Modified: May 12, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Affected (39)

1 product
Bc Java
1 product
Karaf
18 products
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Bouncycastle
Version 1.65
Version 1.66
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.3.2
Configuration C
36 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Before 21.1.2
Version 11.3.2
Version 3.9m0p3
Version 1.2.1
Version 3.0.2.2.0
Oracle
Version 8.0.2
Version 8.1
Version 12.0.0.3.0
From 8.0.0 to 8.2.4.0
From 8.2.0 to 8.2.4
Up to 9.2.5.3
Oracle
Version 8.56
Version 8.57
Version 8.58
Oracle
Version 4.3.0.6.0
Version 4.4.0.0.0
Version 4.4.0.2.0
Version 4.4.0.3.0
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0

References (52)

Source: cve@mitre.org
MitigationPatchThird Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.