CRITICAL · 9.8

CVE-2018-1000613

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsa...

Vulnerability Description

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BouncycastleBc-Java>= 1.58, < 1.60
NetappOncommand Workflow Automation-
OpensuseLeap15.1
OracleApi Gateway11.1.2.4.0
OracleBanking Platform2.6.0
OracleBusiness Process Management Suite11.1.1.9.0
OracleBusiness Transaction Management12.1.0
OracleCommunications Application Session Controller3.7.1
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Convergence3.0.2
OracleCommunications Diameter Signaling Router8.0.0
OracleCommunications Webrtc Session Controller< 7.2
OracleData Integrator12.2.1.3.0
OracleEnterprise Manager Base Platform12.1.0.5.0
OracleEnterprise Manager For Fusion Middleware13.2.0.0
OracleEnterprise Repository11.1.1.7.0
OracleManaged File Transfer12.1.3.0.0
OraclePeoplesoft Enterprise Peopletools8.55
OracleRetail Convenience And Fuel Pos Software2.8.1
OracleRetail Xstore Point Of Service7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1000613?

CVE-2018-1000613 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsa...

How severe is CVE-2018-1000613?

CVE-2018-1000613 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-1000613?

Check the references section above for vendor advisories and patch information. Affected products include: Bouncycastle Bc-Java, Netapp Oncommand Workflow Automation, Opensuse Leap, Oracle Api Gateway, Oracle Banking Platform.