8.1

CVE-2020-28052

Exploit

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BouncycastleBc-java Version1.65
BouncycastleBc-java Version1.66
ApacheKaraf Version4.3.2
OracleBlockchain Platform Version < 21.1.2
OracleCommerce Guided Search Version11.3.2
OracleCommunications Convergence Version3.0.2.2.0
OracleCommunications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
OracleCommunications Session Route Manager Version >= 8.2.0 <= 8.2.4
OracleJd Edwards Enterpriseone Tools Version <= 9.2.5.3
OracleUtilities Framework Version4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleWebcenter Portal Version11.1.1.9.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.78% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
https://www.bouncycastle.org/releasenotes.html
Vendor Advisory
Release Notes
https://github.com/bcgit/bc-java/wiki/CVE-2020-28052
Patch
Third Party Advisory
Mitigation