7.5
CVE-2018-1000180
- EPSS 0.24%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version >= 1.54 <= 1.59
Bouncycastle ≫ Fips Java Api Version <= 1.0.1
Debian ≫ Debian Linux Version9.0
Oracle ≫ Api Gateway Version11.1.2.4.0
Oracle ≫ Business Process Management Suite Version11.1.1.9.0
Oracle ≫ Business Process Management Suite Version12.1.3.0.0
Oracle ≫ Business Process Management Suite Version12.2.1.3.0
Oracle ≫ Business Transaction Management Version12.1.0
Oracle ≫ Communications Application Session Controller Version3.7.1
Oracle ≫ Communications Application Session Controller Version3.8.0
Oracle ≫ Communications Converged Application Server Version < 7.0.0.1
Oracle ≫ Communications Webrtc Session Controller Version < 7.2
Oracle ≫ Enterprise Repository Version12.1.3.0.0
Oracle ≫ Managed File Transfer Version12.1.3.0.0
Oracle ≫ Managed File Transfer Version12.2.1.3.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.55
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.57
Oracle ≫ Retail Convenience And Fuel Pos Software Version2.8.1
Oracle ≫ Retail Xstore Point Of Service Version7.0
Oracle ≫ Retail Xstore Point Of Service Version7.1
Oracle ≫ Webcenter Portal Version11.1.1.9.0
Oracle ≫ Webcenter Portal Version12.2.1.3.0
Oracle ≫ Weblogic Server Version12.1.3.0.0
Netapp ≫ Oncommand Workflow Automation Version-
Redhat ≫ Virtualization Version4.2
Redhat ≫ Jboss Enterprise Application Platform Version7.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.476 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.