First published: Tue Jun 05 2018(Updated: )
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/bouncycastle | 1.60-1 1.60-1+deb10u1 1.68-2 1.72-2 | |
Bouncycastle Fips Java Api | <=1.0.1 | |
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api | >=1.54<=1.59 | |
Debian Debian Linux | =9.0 | |
Oracle API Gateway | =11.1.2.4.0 | |
Oracle Business Process Management Suite | =11.1.1.9.0 | |
Oracle Business Process Management Suite | =12.1.3.0.0 | |
Oracle Business Process Management Suite | =12.2.1.3.0 | |
Oracle Business Transaction Management | =12.1.0 | |
Oracle Communications Application Session Controller | =3.7.1 | |
Oracle Communications Application Session Controller | =3.8.0 | |
Oracle Communications Converged Application Server | <7.0.0.1 | |
Oracle Communications WebRTC Session Controller | <7.2 | |
Oracle Enterprise Repository | =12.1.3.0.0 | |
Oracle Managed File Transfer | =12.1.3.0.0 | |
Oracle Managed File Transfer | =12.2.1.3.0 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.55 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.56 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle Retail Convenience And Fuel Pos Software | =2.8.1 | |
Oracle Retail Xstore Point of Service | =7.0 | |
Oracle Retail Xstore Point of Service | =7.1 | |
Oracle SOA Suite | =12.1.3.0.0 | |
Oracle SOA Suite | =12.2.1.3.0 | |
Oracle WebCenter Portal | =11.1.1.9.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.1.3.0.0 | |
NetApp OnCommand Workflow Automation | ||
Redhat Virtualization | =4.2 | |
Redhat Jboss Enterprise Application Platform | =7.1.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
redhat/bouncycastle | <1.60 | 1.60 |
IBM GDE | <=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security flaw is CVE-2018-1000180.
The severity level of vulnerability CVE-2018-1000180 is high with a severity value of 7.5.
The affected software for vulnerability CVE-2018-1000180 includes Bouncy Castle versions BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1, and earlier.
To fix vulnerability CVE-2018-1000180, update to Bouncy Castle version 1.60 or later.
You can find more information about vulnerability CVE-2018-1000180 on the Bouncy Castle issue tracker and GitHub repositories.