RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDell Bsafe Cert J
APPDell≤ 6.2.4Dell Bsafe Crypto J
APPDell< 6.2.5Dell Bsafe Ssl J
APPDell≤ 6.2.4.1Oracle Application Performance Management
APPOracle13.3.0.013.4.0.0Oracle Communications Network Integrity
APPOracle7.3.27.3.57.3.6Oracle Database
APPOracle12.1.0.212.2.0.118c19cOracle Goldengate
APPOracle< 19.1.0.0.0.210420Oracle Retail Assortment Planning
APPOracle15.0.3.016.0.3.0Oracle Retail Integration Bus
APPOracle14.115.016.0Oracle Retail Predictive Application Server
APPOracle14.1.3.015.0.3.016.0.3.0Oracle Retail Service Backbone
APPOracle14.115.016.0Oracle Retail Store Inventory Management
APPOracle14.0.414.1.315.0.316.0.3Oracle Retail Xstore Point Of Service
APPOracle15.0.316.0.517.0.318.0.219.0.1Oracle Storagetek Acsls
APPOracle8.5.1Oracle Storagetek Tape Analytics Sw Tool
APPOracle2.3Oracle Weblogic Server
APPOracle10.3.6.0.012.2.1.3.012.2.1.4.014.1.1.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Referencje
Powiązane podatności
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2020-14750CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Oracle WebLogic Server — Auth Bypass w komponencie Console (RCE)
CVE-2020-14882CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE bez uwierzytelnienia w konsoli Oracle WebLogic Server
CVE-2020-14644CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Oracle WebLogic Server — przejęcie serwera przez IIOP/T3