4.3
CVSSv2

CVE-2020-15522

Published: 20/05/2021 Updated: 22/06/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Bouncy Castle BC Java prior to 1.66, BC C# .NET prior to 1.8.7, BC-FJA prior to 1.0.1.2, 1.0.2.1, and BC-FNA prior to 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bouncycastle bc-csharp

bouncycastle bouncy castle fips .net api

bouncycastle legion-of-the-bouncy-castle-fips-java-api

bouncycastle the bouncy castle crypto package for java

Vendor Advisories

Synopsis Important: Red Hat Integration Camel-K 164 release and security update Type/Severity Security Advisory: Important Topic A micro version update (from 163 to 164) is now available for Red Hat Integration Camel K that includes bug fixes and enhancements The purpose of this text-only errata is to inform you about the security issu ...
Synopsis Moderate: Red Hat Integration Camel Extensions for Quarkus 221 security update Type/Severity Security Advisory: Moderate Topic A security update to Red Hat Integration Camel Extensions for Quarkus 22 is now available The purpose of this text-only errata is to inform you about the security issues fixedRed Hat Product Security has ...
No description is available for this CVE ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-1695, CVE-2020-1723, CVE-2020-1725, CVE-2020-10770, CVE-2020-14302, CVE-2020-15522, CVE-2020-25711, CVE-2020-27838, CVE-2020-28052, CVE-2020-28491, CVE-2021-3424, CVE-2021-3712, CVE-2021-20195, CVE-2021-20202, CVE-2021-20222, CVE-2021-20262, CVE-2021-21290, C ...

Github Repositories

This modified open source code of openpdf 1.0.5 https://github.com/LibrePDF/OpenPDF/tree/1.0.5

OpenPDF is a Java PDF library, forked from iText OpenPDF is a Java library for creating and editing PDF files with a LGPL and MPL open source license OpenPDF is based on a fork of iText 4 We welcome contributions from other developers Please feel free to submit pull-requests and bugreports to this GitHub repository OpenPDF version 104 released 2017-10-11 Get version

The Box SDK for Java.

Box Java SDK The Box Java SDK for interacting with the Box Content API Latest Release Latest release can be found here Upgrades You can read about how to migrate to the 4 version here Versions We use a modified version of Semantic Versioning for all changes See version strategy for details which is effective from 30 July 2022 Supported Version Only the current MAJOR v