CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
2020-01-24T15:15:14.093
2024-11-21T05:36:52.113
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vt | cryptacular | < 1.1.4 | Yes |
Application | vt | cryptacular | < 1.2.4 | Yes |
Application | oracle | communications_services_gatekeeper | 7.0 | Yes |
Application | oracle | webcenter_sites | 12.2.1.3.0 | Yes |
Application | oracle | webcenter_sites | 12.2.1.4.0 | Yes |
Application | oracle | weblogic_server | 12.2.1.4.0 | Yes |
Application | oracle | weblogic_server | 14.1.1.0.0 | Yes |