First published: Tue Oct 08 2019(Updated: )
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api | =1.63 | |
Apache TomEE | =7.0.7 | |
Apache TomEE | =7.1.2 | |
Apache TomEE | =8.0.1 | |
Netapp Active Iq Unified Manager Linux | >=7.3 | |
Netapp Active Iq Unified Manager Windows | >=7.3 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
NetApp OnCommand API Services | ||
NetApp OnCommand Workflow Automation | ||
NetApp Service Level Manager | ||
Oracle Business Process Management Suite | =12.2.1.3.0 | |
Oracle Business Process Management Suite | =12.2.1.4.0 | |
Oracle Communications Convergence | >=3.0.1.0<=3.0.2.1 | |
Oracle Communications Diameter Signaling Router | >=8.0.0<=8.2.2 | |
Oracle Communications Session Route Manager | >=8.2.0<=8.2.2 | |
Oracle Data Integrator | =12.2.1.4.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6<=8.0.9 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 | |
Oracle Hospitality Guest Access | =4.2.0 | |
Oracle Managed File Transfer | =12.2.1.3.0 | |
Oracle Managed File Transfer | =12.2.1.4.0 | |
Oracle Peoplesoft Enterprise Hcm Global Payroll Switzerland | =9.2 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.56 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle Retail Xstore Point of Service | =18.0.1 | |
Oracle SOA Suite | =12.2.1.3.0 | |
Oracle SOA Suite | =12.2.1.4.0 | |
Oracle WebCenter Portal | =11.1.1.9.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17359 is a vulnerability in the ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 that can trigger a large attempted memory allocation, leading to an OutOfMemoryError.
CVE-2019-17359 has a severity rating of 7.5 (High).
The affected software versions are Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.63, Apache TomEE 7.0.7, Apache TomEE 7.1.2, Apache TomEE 8.0.1, Netapp Active Iq Unified Manager (Linux) 7.3 and later, Netapp Active Iq Unified Manager (Windows) 7.3 and later, Netapp Active Iq Unified Manager (VMware vSphere Client) 9.5 and later, NetApp OnCommand API Services, NetApp OnCommand Workflow Automation, NetApp Service Level Manager, Oracle Business Process Management Suite 12.2.1.3.0 and 12.2.1.4.0, Oracle Communications Convergence 3.0.1.0 to 3.0.2.1, Oracle Communications Diameter Signaling Router 8.0.0 to 8.2.2, Oracle Communications Session Route Manager 8.2.0 to 8.2.2, Oracle Data Integrator 12.2.1.4.0, Oracle Financial Services Analytical Applications Infrastructure 8.0.6 to 8.0.9, Oracle FLEXCUBE Private Banking 12.0.0 and 12.1.0, Oracle Hospitality Guest Access 4.2.0, Oracle Managed File Transfer 12.2.1.3.0 and 12.2.1.4.0, Oracle Peoplesoft Enterprise Hcm Global Payroll Switzerland 9.2, Oracle PeopleSoft Enterprise PeopleTools 8.56, 8.57, and 8.58, Oracle Retail Xstore Point of Service 18.0.1, Oracle SOA Suite 12.2.1.3.0 and 12.2.1.4.0, Oracle WebCenter Portal 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0, and Oracle WebLogic Server 12.2.1.3.0 and 12.2.1.4.0.
You can fix the CVE-2019-17359 vulnerability by updating the affected software versions to the patched versions. For Bouncy Castle Crypto, update to version 1.64. For other software, refer to the vendor's security advisory for the appropriate patches or updates.
Yes, you can find more information about CVE-2019-17359 in the following references: [Reference 1](https://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209@%3Ccommits.tomee.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d@%3Ccommits.tomee.apache.org%3E), [Reference 3](https://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27@%3Ccommits.tomee.apache.org%3E).
The Common Weakness Enumeration (CWE) ID for CVE-2019-17359 is CWE-770.