← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-1000613

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:4.77%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
bouncycastle bc-java all
netapp oncommand_workflow_automation all
opensuse leap 15.1
oracle api_gateway 11.1.2.4.0
oracle banking_platform 2.6.0, 2.6.1, 2.6.2
oracle business_process_management_suite 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0
oracle business_transaction_management 12.1.0
oracle communications_application_session_controller 3.7.1, 3.8.0
oracle communications_converged_application_server 7.0.0.1
oracle communications_convergence 3.0.2
oracle communications_diameter_signaling_router 8.0.0, 8.1, 8.2, 8.2.1
oracle communications_webrtc_session_controller 7.2
oracle data_integrator 12.2.1.3.0
oracle enterprise_manager_base_platform 12.1.0.5.0, 13.2.0.0, 13.3.0.0
oracle enterprise_manager_for_fusion_middleware 13.2.0.0, 13.3.0.0
oracle enterprise_repository 11.1.1.7.0, 12.1.3.0.0
oracle managed_file_transfer 12.1.3.0.0, 12.2.1.3.0
oracle peoplesoft_enterprise_peopletools 8.55, 8.56, 8.57
oracle retail_convenience_and_fuel_pos_software 2.8.1
oracle retail_xstore_point_of_service 7.0, 7.1
oracle soa_suite 12.1.3.0.0, 12.2.1.3.0
oracle utilities_network_management_system 1.12.0.3, 2.3.0.0, 2.3.0.1, 2.3.0.2
oracle webcenter_portal 11.1.1.9.0, 12.2.1.3.0
oracle weblogic_server 12.2.1.3

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.767%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-06-29T00:00:00
Published2018-07-09T20:00:00
Patch Date2018-03-02
Last Updated2024-11-14T20:37:00

LINK COPIED TO CLIPBOARD