RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDell Bsafe Cert J
APPDell≤ 6.2.4Dell Bsafe Crypto J
APPDell< 6.2.5Dell Bsafe Ssl J
APPDell≤ 6.2.4.1Mcafee Threat Intelligence Exchange Server
APPMcafee3.0.02.0.0 – 2.3.1Oracle Application Performance Management
APPOracle13.3.0.013.4.0.0Oracle Communications Network Integrity
APPOracle7.3.27.3.57.3.6Oracle Communications Unified Inventory Management
APPOracle7.3.27.3.47.3.57.4.07.4.1Oracle Database
APPOracle12.1.0.212.2.0.118c19cOracle Goldengate
APPOracle19.1.0.0.0.210420< 19.1.0.0.0.210420Oracle Retail Assortment Planning
APPOracle15.0.3.016.0.3.0Oracle Retail Integration Bus
APPOracle14.115.016.0Oracle Retail Predictive Application Server
APPOracle14.1.3.015.0.3.016.0.3.0Oracle Retail Service Backbone
APPOracle14.115.016.0Oracle Retail Store Inventory Management
APPOracle14.0.414.1.315.0.316.0.3Oracle Retail Xstore Point Of Service
APPOracle15.0.316.0.517.0.318.0.219.0.1Oracle Storagetek Tape Analytics Sw Tool
APPOracle2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2020-2555CRITICAL9.8⚠ KEVPL ✓same product
RCE przez deserializację w Oracle Coherence via protokół T3
CVE-2019-2725CRITICAL9.8⚠ KEVPL ✓same product
RCE w Oracle WebLogic Server — przejęcie serwera bez uwierzytelnienia
CVE-2015-4852CRITICAL9.8⚠ KEVPL ✓same product
RCE w Oracle WebLogic Server poprzez deserializację w protokole T3