9.8
CVE-2018-1000613
- EPSS 4.77%
- Veröffentlicht 09.07.2018 20:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
- Erkennungen
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version >= 1.58 < 1.60
Netapp ≫ Oncommand Workflow Automation Version -
Oracle ≫ Api Gateway Version 11.1.2.4.0
Oracle ≫ Banking Platform Version 2.6.0
Oracle ≫ Banking Platform Version 2.6.1
Oracle ≫ Banking Platform Version 2.6.2
Oracle ≫ Business Process Management Suite Version 11.1.1.9.0
Oracle ≫ Business Process Management Suite Version 12.1.3.0.0
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Transaction Management Version 12.1.0
Oracle ≫ Communications Application Session Controller Version 3.7.1
Oracle ≫ Communications Application Session Controller Version 3.8.0
Oracle ≫ Communications Converged Application Server Version < 7.0.0.1
Oracle ≫ Communications Converged Application Server Version 7.0.0.1
Oracle ≫ Communications Convergence Version 3.0.2
Oracle ≫ Communications Diameter Signaling Router Version 8.0.0
Oracle ≫ Communications Diameter Signaling Router Version 8.1
Oracle ≫ Communications Diameter Signaling Router Version 8.2
Oracle ≫ Communications Diameter Signaling Router Version 8.2.1
Oracle ≫ Communications Webrtc Session Controller Version < 7.2
Oracle ≫ Communications Webrtc Session Controller Version 7.2
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Enterprise Manager Base Platform Version 12.1.0.5.0
Oracle ≫ Enterprise Manager Base Platform Version 13.2.0.0
Oracle ≫ Enterprise Manager Base Platform Version 13.3.0.0
Oracle ≫ Enterprise Manager For Fusion Middleware Version 13.2.0.0
Oracle ≫ Enterprise Manager For Fusion Middleware Version 13.3.0.0
Oracle ≫ Enterprise Repository Version 11.1.1.7.0
Oracle ≫ Enterprise Repository Version 12.1.3.0.0
Oracle ≫ Managed File Transfer Version 12.1.3.0.0
Oracle ≫ Managed File Transfer Version 12.2.1.3.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.55
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.57
Oracle ≫ Retail Convenience And Fuel Pos Software Version 2.8.1
Oracle ≫ Retail Xstore Point Of Service Version 7.0
Oracle ≫ Retail Xstore Point Of Service Version 7.1
Oracle ≫ Utilities Network Management System Version 1.12.0.3
Oracle ≫ Utilities Network Management System Version 2.3.0.0
Oracle ≫ Utilities Network Management System Version 2.3.0.1
Oracle ≫ Utilities Network Management System Version 2.3.0.2
Oracle ≫ Webcenter Portal Version 11.1.1.9.0
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.77% | 0.908 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html
https://security.netapp.com/advisory/ntap-20190204-0003/
https://github.com/bcgit/bc-java/commit/4092ede58da51af9a21e4825fbad0d9a3ef5a223#diff-2c06e2edef41db889ee14899e12bd574
https://github.com/bcgit/bc-java/commit/cd98322b171b15b3f88c5ec871175147893c31e6#diff-148a6c098af0199192d6aede960f45dc