6.5

CVE-2019-3738

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Bsafe Cert-j Version <= 6.2.4
Dell ≫ Bsafe Crypto-j Version < 6.2.5
Dell ≫ Bsafe Ssl-j Version <= 6.2.4.1
Mcafee ≫ Threat Intelligence Exchange Server Version >= 2.0.0 <= 2.3.1
Oracle ≫ Database Version 12.1.0.2 SwEdition enterprise
Oracle ≫ Database Version 12.2.0.1 SwEdition enterprise
Oracle ≫ Database Version 18c SwEdition enterprise
Oracle ≫ Database Version 19c SwEdition enterprise
Oracle ≫ Goldengate Version < 19.1.0.0.0.210420
Oracle ≫ Goldengate Version 19.1.0.0.0.210420
Oracle ≫ Retail Assortment Planning Version 15.0.3.0
Oracle ≫ Retail Assortment Planning Version 16.0.3.0
Oracle ≫ Retail Integration Bus Version 14.1
Oracle ≫ Retail Integration Bus Version 15.0
Oracle ≫ Retail Integration Bus Version 16.0
Oracle ≫ Retail Service Backbone Version 14.1
Oracle ≫ Retail Service Backbone Version 15.0
Oracle ≫ Retail Service Backbone Version 16.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.68% 0.739
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
EMC 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10318
Third Party Advisory
https://www.dell.com/support/security/en-us/details/DOC-106556/DSA-2019-094-RSA-BSAFE&#174%3B-Crypto-J-Multiple-Security-Vulnerabilities