An issue exists in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bouncycastle legion-of-the-bouncy-castle-java-crytography-api 1.66 |
||
bouncycastle legion-of-the-bouncy-castle-java-crytography-api 1.65 |
||
apache karaf 4.3.2 |
||
oracle peoplesoft enterprise peopletools 8.56 |
||
oracle webcenter portal 12.2.1.3.0 |
||
oracle webcenter portal 11.1.1.9.0 |
||
oracle peoplesoft enterprise peopletools 8.57 |
||
oracle utilities framework 4.3.0.6.0 |
||
oracle utilities framework 4.4.0.0.0 |
||
oracle peoplesoft enterprise peopletools 8.58 |
||
oracle webcenter portal 12.2.1.4.0 |
||
oracle utilities framework 4.4.0.2.0 |
||
oracle banking extensibility workbench 14.3.0 |
||
oracle banking virtual account management 14.3.0 |
||
oracle banking credit facilities process management 14.3.0 |
||
oracle banking corporate lending process management 14.3.0 |
||
oracle communications messaging server 8.1 |
||
oracle commerce guided search 11.3.2 |
||
oracle communications messaging server 8.0.2 |
||
oracle utilities framework 4.4.0.3.0 |
||
oracle communications cloud native core network slice selection function 1.2.1 |
||
oracle communications pricing design center 12.0.0.3.0 |
||
oracle communications application session controller 3.9m0p3 |
||
oracle jd edwards enterpriseone tools |
||
oracle banking virtual account management 14.2.0 |
||
oracle banking virtual account management 14.5.0 |
||
oracle banking supply chain finance 14.2.0 |
||
oracle banking credit facilities process management 14.2.0 |
||
oracle banking credit facilities process management 14.5.0 |
||
oracle banking corporate lending process management 14.2.0 |
||
oracle banking corporate lending process management 14.5.0 |
||
oracle communications session report manager |
||
oracle banking supply chain finance 14.5.0 |
||
oracle banking supply chain finance 14.3.0 |
||
oracle banking extensibility workbench 14.2.0 |
||
oracle banking extensibility workbench 14.5.0 |
||
oracle communications session route manager |
||
oracle communications convergence 3.0.2.2.0 |
||
oracle blockchain platform |