Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3739


RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.


Published

2019-09-18T23:15:11.110

Last Modified

2024-11-21T04:42:26.480

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310
  • Type: Secondary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell bsafe_cert-j ≤ 6.2.4 Yes
Application dell bsafe_crypto-j < 6.2.5 Yes
Application dell bsafe_ssl-j ≤ 6.2.4.1 Yes
Application oracle application_performance_management 13.3.0.0 Yes
Application oracle application_performance_management 13.4.0.0 Yes
Application oracle communications_network_integrity 7.3.2 Yes
Application oracle communications_network_integrity 7.3.5 Yes
Application oracle communications_network_integrity 7.3.6 Yes
Application oracle database 12.1.0.2 Yes
Application oracle database 12.2.0.1 Yes
Application oracle database 18c Yes
Application oracle database 19c Yes
Application oracle goldengate < 19.1.0.0.0.210420 Yes
Application oracle retail_assortment_planning 15.0.3.0 Yes
Application oracle retail_assortment_planning 16.0.3.0 Yes
Application oracle retail_integration_bus 14.1 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_predictive_application_server 14.1.3.0 Yes
Application oracle retail_predictive_application_server 15.0.3.0 Yes
Application oracle retail_predictive_application_server 16.0.3.0 Yes
Application oracle retail_service_backbone 14.1 Yes
Application oracle retail_service_backbone 15.0 Yes
Application oracle retail_service_backbone 16.0 Yes
Application oracle retail_store_inventory_management 14.0.4 Yes
Application oracle retail_store_inventory_management 14.1.3 Yes
Application oracle retail_store_inventory_management 15.0.3 Yes
Application oracle retail_store_inventory_management 16.0.3 Yes
Application oracle retail_xstore_point_of_service 15.0.3 Yes
Application oracle retail_xstore_point_of_service 16.0.5 Yes
Application oracle retail_xstore_point_of_service 17.0.3 Yes
Application oracle retail_xstore_point_of_service 18.0.2 Yes
Application oracle retail_xstore_point_of_service 19.0.1 Yes
Application oracle storagetek_acsls 8.5.1 Yes
Application oracle storagetek_tape_analytics_sw_tool 2.3 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes

References