7.5

CVE-2019-17359

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BouncycastleBc-java Version1.63
ApacheTomee Version7.0.7
ApacheTomee Version7.1.2
ApacheTomee Version8.0.1
NetappActive Iq Unified Manager SwPlatformlinux Version >= 7.3
NetappActive Iq Unified Manager SwPlatformwindows Version >= 7.3
NetappActive Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
OracleCommunications Convergence Version >= 3.0.1.0 <= 3.0.2.1
OracleCommunications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
OracleCommunications Session Route Manager Version >= 8.2.0 <= 8.2.2
OracleData Integrator Version12.2.1.4.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleHospitality Guest Access Version4.2.0
OracleManaged File Transfer Version12.2.1.3.0
OracleManaged File Transfer Version12.2.1.4.0
OracleSoa Suite Version12.2.1.3.0
OracleSoa Suite Version12.2.1.4.0
OracleWebcenter Portal Version11.1.1.9.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.63% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

https://www.bouncycastle.org/releasenotes.html
Vendor Advisory
Release Notes