First published: Mon Jul 09 2018(Updated: )
Legion of the Bouncy Castle Java Cryptography APIs could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe reflection flaw in XMSS/XMSS^MT private key deserialization. By using specially-crafted private key, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api | >=1.58<1.60 | |
NetApp OnCommand Workflow Automation | ||
openSUSE Leap | =15.1 | |
Oracle API Gateway | =11.1.2.4.0 | |
Oracle Banking Platform | =2.6.0 | |
Oracle Banking Platform | =2.6.1 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Business Process Management Suite | =11.1.1.9.0 | |
Oracle Business Process Management Suite | =12.1.3.0.0 | |
Oracle Business Process Management Suite | =12.2.1.3.0 | |
Oracle Business Transaction Management | =12.1.0 | |
Oracle Communications Application Session Controller | =3.7.1 | |
Oracle Communications Application Session Controller | =3.8.0 | |
Oracle Communications Converged Application Server | <7.0.0.1 | |
Oracle Communications Converged Application Server | =7.0.0.1 | |
Oracle Communications Convergence | =3.0.2 | |
Oracle Communications Diameter Signaling Router | =8.0.0 | |
Oracle Communications Diameter Signaling Router | =8.1 | |
Oracle Communications Diameter Signaling Router | =8.2 | |
Oracle Communications Diameter Signaling Router | =8.2.1 | |
Oracle Communications WebRTC Session Controller | <7.2 | |
Oracle Communications WebRTC Session Controller | =7.2 | |
Oracle Data Integrator | =12.2.1.3.0 | |
Oracle Enterprise Manager Base Platform | =12.1.0.5.0 | |
Oracle Enterprise Manager Base Platform | =13.2.0.0 | |
Oracle Enterprise Manager Base Platform | =13.3.0.0 | |
Oracle Enterprise Manager For Fusion Middleware | =13.2.0.0 | |
Oracle Enterprise Manager For Fusion Middleware | =13.3.0.0 | |
Oracle Enterprise Repository | =11.1.1.7.0 | |
Oracle Enterprise Repository | =12.1.3.0.0 | |
Oracle Managed File Transfer | =12.1.3.0.0 | |
Oracle Managed File Transfer | =12.2.1.3.0 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.55 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.56 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle Retail Convenience And Fuel Pos Software | =2.8.1 | |
Oracle Retail Xstore Point of Service | =7.0 | |
Oracle Retail Xstore Point of Service | =7.1 | |
Oracle SOA Suite | =12.1.3.0.0 | |
Oracle SOA Suite | =12.2.1.3.0 | |
Oracle Utilities Network Management System | =1.12.0.3 | |
Oracle Utilities Network Management System | =2.3.0.0 | |
Oracle Utilities Network Management System | =2.3.0.1 | |
Oracle Utilities Network Management System | =2.3.0.2 | |
Oracle WebCenter Portal | =11.1.1.9.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.3 | |
maven/org.bouncycastle:bcprov-jdk15on | >=1.57<1.60 | 1.60 |
IBM GDE | <=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000613 is a vulnerability in Legion of the Bouncy Castle Java Cryptography APIs that allows a remote attacker to execute arbitrary code.
The severity of CVE-2018-1000613 is critical with a CVSS score of 9.8.
CVE-2018-1000613 affects versions 1.57 to 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.
To fix CVE-2018-1000613, upgrade to version 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.
You can learn more about CVE-2018-1000613 at the following references: [link1](https://nvd.nist.gov/vuln/detail/CVE-2018-1000613), [link2](https://github.com/bcgit/bc-java/commit/4092ede58da51af9a21e4825fbad0d9a3ef5a223#diff-2c06e2edef41db889ee14899e12bd574), [link3](https://github.com/bcgit/bc-java/commit/cd98322b171b15b3f88c5ec871175147893c31e6#diff-148a6c098af0199192d6aede960f45dc).