5
CVSSv2

CVE-2018-1000180

Published: 05/06/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and previous versions have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bouncycastle fips java api

bouncycastle legion-of-the-bouncy-castle-java-crytography-api

debian debian linux 9.0

oracle retail xstore point of service 7.1

oracle api gateway 11.1.2.4.0

oracle weblogic server 12.1.3.0.0

oracle enterprise repository 12.1.3.0.0

oracle retail xstore point of service 7.0

oracle peoplesoft enterprise peopletools 8.55

oracle peoplesoft enterprise peopletools 8.56

oracle webcenter portal 12.2.1.3.0

oracle webcenter portal 11.1.1.9.0

oracle business process management suite 12.1.3.0.0

oracle business process management suite 12.2.1.3.0

oracle business process management suite 11.1.1.9.0

oracle soa suite 12.1.3.0.0

oracle soa suite 12.2.1.3.0

oracle peoplesoft enterprise peopletools 8.57

oracle managed file transfer 12.2.1.3.0

oracle communications converged application server

oracle communications webrtc session controller

oracle retail convenience and fuel pos software 2.8.1

oracle communications application session controller 3.7.1

oracle communications application session controller 3.8.0

oracle managed file transfer 12.1.3.0.0

oracle business transaction management 12.1.0

netapp oncommand workflow automation -

redhat virtualization 4.2

redhat jboss_enterprise_application_platform 7.1.0

Vendor Advisories

Debian Bug report logs - #900843 bouncycastle: CVE-2018-1000180 Package: src:bouncycastle; Maintainer for src:bouncycastle is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 5 Jun 2018 20:27:02 UTC Severity: grave Tags: patch, s ...
It was discovered that the low-level interface to the RSA key pair generator of Bouncy Castle (a Java implementation of cryptographic algorithms) could perform less Miller-Rabin primality tests than expected For the stable distribution (stretch), this problem has been fixed in version 156-1+deb9u2 We recommend that you upgrade your bouncycastle ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 714 on RHEL7 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 714 on RHEL 6 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 71 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer PortalRed Hat Product Security has rated this update as having a secu ...
Synopsis Important: Fuse 71 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed s ...
Synopsis Important: Red Hat OpenShift Application Runtimes Thorntail 240 security & bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Application RuntimesRed Hat Product Security has rated this update as having a security impact of Import ...
Synopsis Important: rhvm-appliance security update Type/Severity Security Advisory: Important Topic An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vuln ...
Synopsis Important: Red Hat Single Sign-On 724 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 72 from theCustomer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulner ...

Github Repositories

Java SDK for CyberSource Simple Order API

CyberSource Simple Order API for Java Package Managers Maven To install the cybersource-sdk-java from central repository, add dependency to your application pomxml as below <dependency> <groupId>comcybersource</groupId> <artifactId>cybersource-sdk-java</artifactId> <version>6213&

References