CWE
470 502
Advisory Published
Advisory Published
Updated

CVE-2018-1000613

First published: Mon Jul 09 2018(Updated: )

Legion of the Bouncy Castle Java Cryptography APIs could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe reflection flaw in XMSS/XMSS^MT private key deserialization. By using specially-crafted private key, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Credit: cve@mitre.org cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api>=1.58<1.60
NetApp OnCommand Workflow Automation
openSUSE Leap=15.1
Oracle API Gateway=11.1.2.4.0
Oracle Banking Platform=2.6.0
Oracle Banking Platform=2.6.1
Oracle Banking Platform=2.6.2
Oracle Business Process Management Suite=11.1.1.9.0
Oracle Business Process Management Suite=12.1.3.0.0
Oracle Business Process Management Suite=12.2.1.3.0
Oracle Business Transaction Management=12.1.0
Oracle Communications Application Session Controller=3.7.1
Oracle Communications Application Session Controller=3.8.0
Oracle Communications Converged Application Server<7.0.0.1
Oracle Communications Converged Application Server=7.0.0.1
Oracle Communications Convergence=3.0.2
Oracle Communications Diameter Signaling Router=8.0.0
Oracle Communications Diameter Signaling Router=8.1
Oracle Communications Diameter Signaling Router=8.2
Oracle Communications Diameter Signaling Router=8.2.1
Oracle Communications WebRTC Session Controller<7.2
Oracle Communications WebRTC Session Controller=7.2
Oracle Data Integrator=12.2.1.3.0
Oracle Enterprise Manager Base Platform=12.1.0.5.0
Oracle Enterprise Manager Base Platform=13.2.0.0
Oracle Enterprise Manager Base Platform=13.3.0.0
Oracle Enterprise Manager For Fusion Middleware=13.2.0.0
Oracle Enterprise Manager For Fusion Middleware=13.3.0.0
Oracle Enterprise Repository=11.1.1.7.0
Oracle Enterprise Repository=12.1.3.0.0
Oracle Managed File Transfer=12.1.3.0.0
Oracle Managed File Transfer=12.2.1.3.0
Oracle PeopleSoft Enterprise PeopleTools=8.55
Oracle PeopleSoft Enterprise PeopleTools=8.56
Oracle PeopleSoft Enterprise PeopleTools=8.57
Oracle Retail Convenience And Fuel Pos Software=2.8.1
Oracle Retail Xstore Point of Service=7.0
Oracle Retail Xstore Point of Service=7.1
Oracle SOA Suite=12.1.3.0.0
Oracle SOA Suite=12.2.1.3.0
Oracle Utilities Network Management System=1.12.0.3
Oracle Utilities Network Management System=2.3.0.0
Oracle Utilities Network Management System=2.3.0.1
Oracle Utilities Network Management System=2.3.0.2
Oracle WebCenter Portal=11.1.1.9.0
Oracle WebCenter Portal=12.2.1.3.0
Oracle WebLogic Server=12.2.1.3
maven/org.bouncycastle:bcprov-jdk15on>=1.57<1.60
1.60
IBM GDE<=3.0.0.2

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is CVE-2018-1000613?

    CVE-2018-1000613 is a vulnerability in Legion of the Bouncy Castle Java Cryptography APIs that allows a remote attacker to execute arbitrary code.

  • What is the severity of CVE-2018-1000613?

    The severity of CVE-2018-1000613 is critical with a CVSS score of 9.8.

  • How does CVE-2018-1000613 affect the Legion of the Bouncy Castle Java Cryptography APIs?

    CVE-2018-1000613 affects versions 1.57 to 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.

  • How can I fix CVE-2018-1000613?

    To fix CVE-2018-1000613, upgrade to version 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.

  • How can I learn more about CVE-2018-1000613?

    You can learn more about CVE-2018-1000613 at the following references: [link1](https://nvd.nist.gov/vuln/detail/CVE-2018-1000613), [link2](https://github.com/bcgit/bc-java/commit/4092ede58da51af9a21e4825fbad0d9a3ef5a223#diff-2c06e2edef41db889ee14899e12bd574), [link3](https://github.com/bcgit/bc-java/commit/cd98322b171b15b3f88c5ec871175147893c31e6#diff-148a6c098af0199192d6aede960f45dc).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203