Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3740


RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.


Published

2019-09-18T23:15:11.173

Last Modified

2024-11-21T04:42:26.680

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-310
  • Type: Primary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell bsafe_cert-j ≤ 6.2.4 Yes
Application dell bsafe_crypto-j < 6.2.5 Yes
Application dell bsafe_ssl-j ≤ 6.2.4.1 Yes
Application oracle application_performance_management 13.3.0.0 Yes
Application oracle application_performance_management 13.4.0.0 Yes
Application oracle communications_network_integrity 7.3.2 Yes
Application oracle communications_network_integrity 7.3.5 Yes
Application oracle communications_network_integrity 7.3.6 Yes
Application oracle communications_unified_inventory_management 7.3.2 Yes
Application oracle communications_unified_inventory_management 7.3.4 Yes
Application oracle communications_unified_inventory_management 7.3.5 Yes
Application oracle communications_unified_inventory_management 7.4.0 Yes
Application oracle communications_unified_inventory_management 7.4.1 Yes
Application oracle database 12.1.0.2 Yes
Application oracle database 12.2.0.1 Yes
Application oracle database 18c Yes
Application oracle database 19c Yes
Application oracle global_lifecycle_management_opatch < 12.2.0.1.22 Yes
Application oracle goldengate < 19.1.0.0.0.210420 Yes
Application oracle retail_assortment_planning 15.0.3.0 Yes
Application oracle retail_assortment_planning 16.0.3.0 Yes
Application oracle retail_integration_bus 14.1 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_predictive_application_server 14.1.3.0 Yes
Application oracle retail_predictive_application_server 15.0 Yes
Application oracle retail_predictive_application_server 15.0.3.0 Yes
Application oracle retail_predictive_application_server 16.0.3.0 Yes
Application oracle retail_service_backbone 14.1 Yes
Application oracle retail_service_backbone 15.0 Yes
Application oracle retail_service_backbone 16.0 Yes
Application oracle retail_store_inventory_management 14.0.4 Yes
Application oracle retail_store_inventory_management 14.1.3 Yes
Application oracle retail_store_inventory_management 15.0.3 Yes
Application oracle retail_store_inventory_management 16.0.3 Yes
Application oracle retail_xstore_point_of_service 15.0.3 Yes
Application oracle retail_xstore_point_of_service 16.0.5 Yes
Application oracle retail_xstore_point_of_service 17.0.3 Yes
Application oracle retail_xstore_point_of_service 18.0.2 Yes
Application oracle retail_xstore_point_of_service 19.0.1 Yes
Application oracle storagetek_acsls 8.5.1 Yes
Application oracle storagetek_tape_analytics_sw_tool 2.3 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes

References