MEDIUM · 6.5

CVE-2019-3739

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially ...

Vulnerability Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DellBsafe Cert-J<= 6.2.4
DellBsafe Crypto-J< 6.2.5
DellBsafe Ssl-J<= 6.2.4.1
OracleApplication Performance Management13.3.0.0
OracleCommunications Network Integrity7.3.2
OracleDatabase12.1.0.2
OracleGoldengate< 19.1.0.0.0.210420
OracleRetail Assortment Planning15.0.3.0
OracleRetail Integration Bus14.1
OracleRetail Predictive Application Server14.1.3.0
OracleRetail Service Backbone14.1
OracleRetail Store Inventory Management14.0.4
OracleRetail Xstore Point Of Service15.0.3
OracleStoragetek Acsls8.5.1
OracleStoragetek Tape Analytics Sw Tool2.3
OracleWeblogic Server10.3.6.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3739?

CVE-2019-3739 is a vulnerability with a CVSS score of 6.5 (MEDIUM). RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially ...

How severe is CVE-2019-3739?

CVE-2019-3739 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-3739?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Bsafe Cert-J, Dell Bsafe Crypto-J, Dell Bsafe Ssl-J, Oracle Application Performance Management, Oracle Communications Network Integrity.