CVE-2019-3740: Medium severity dell bsafe cert-j vulnerability
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3740?
CVE-2019-3740 is a vulnerability in RSA BSAFE Crypto-J versions prior to 6.2.5 that allows for information exposure through timing discrepancies during DSA key generation.
What is the severity of CVE-2019-3740?
The severity of CVE-2019-3740 is rated as medium, with a severity score of 6.5.
Which software versions are affected by CVE-2019-3740?
RSA BSAFE Crypto-J versions prior to 6.2.5 are affected by CVE-2019-3740.
How can a malicious remote attacker exploit CVE-2019-3740?
A malicious remote attacker can potentially exploit CVE-2019-3740 to recover DSA keys.
Where can I find more information about CVE-2019-3740?
You can find more information about CVE-2019-3740 at the following references: [Reference 1](https://www.dell.com/support/security/en-us/details/DOC-106556/DSA-2019-094-RSA-BSAFE®-Crypto-J-Multiple-Security-Vulnerabilities), [Reference 2](https://www.oracle.com//security-alerts/cpujul2021.html), [Reference 3](https://www.oracle.com/security-alerts/cpuApr2021.html).