← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-28052

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
EPSS Probability:7.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
bouncycastle bc-java 1.65, 1.66
apache karaf 4.3.2
oracle banking_corporate_lending_process_management 14.2.0, 14.3.0, 14.5.0
oracle banking_credit_facilities_process_management 14.2.0, 14.3.0, 14.5.0
oracle banking_extensibility_workbench 14.2.0, 14.3.0, 14.5.0
oracle banking_supply_chain_finance 14.2.0, 14.3.0, 14.5.0
oracle banking_virtual_account_management 14.2.0, 14.3.0, 14.5.0
oracle blockchain_platform all
oracle commerce_guided_search 11.3.2
oracle communications_application_session_controller 3.9m0p3
oracle communications_cloud_native_core_network_slice_selection_function 1.2.1
oracle communications_convergence 3.0.2.2.0
oracle communications_pricing_design_center 12.0.0.3.0
oracle communications_session_report_manager all
oracle communications_session_route_manager all
oracle jd_edwards_enterpriseone_tools all
oracle peoplesoft_enterprise_peopletools 8.56, 8.57, 8.58
oracle utilities_framework 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0
oracle webcenter_portal 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
oracle communications_messaging_server 8.0.2, 8.1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
7.140%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-11-02T00:00:00
Published2020-12-18T00:52:48
Last Updated2024-08-04T16:33:56

LINK COPIED TO CLIPBOARD