REDHAT-BUG-2458641: High severity Bouncy Castle BC-JAVA bcprov vulnerability
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.84.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458641?
The severity of REDHAT-BUG-2458641 is classified as high, with a CVSS score of 7.
How do I fix REDHAT-BUG-2458641?
To fix REDHAT-BUG-2458641, upgrade the Bouncy Castle BC-JAVA bcprov library to version 1.84 or later.
What systems are affected by REDHAT-BUG-2458641?
REDHAT-BUG-2458641 affects all versions of Bouncy Castle BC-JAVA bcprov from 1.74 up to but not including 1.84.
What type of vulnerability is REDHAT-BUG-2458641?
REDHAT-BUG-2458641 is categorized as an LDAP injection vulnerability.
Who is responsible for the vulnerability REDHAT-BUG-2458641?
REDHAT-BUG-2458641 is associated with program files maintained by Legion of the Bouncy Castle Inc.