HIGH · 8.1

CVE-2020-28052

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect pass...

Vulnerability Description

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BouncycastleBc-Java1.65
ApacheKaraf4.3.2
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Extensibility Workbench14.2.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Virtual Account Management14.2.0
OracleBlockchain Platform< 21.1.2
OracleCommerce Guided Search11.3.2
OracleCommunications Application Session Controller3.9m0p3
OracleCommunications Cloud Native Core Network Slice Selection Function1.2.1
OracleCommunications Convergence3.0.2.2.0
OracleCommunications Pricing Design Center12.0.0.3.0
OracleCommunications Session Report Manager>= 8.0.0, <= 8.2.4.0
OracleCommunications Session Route Manager>= 8.2.0, <= 8.2.4
OracleJd Edwards Enterpriseone Tools<= 9.2.5.3
OraclePeoplesoft Enterprise Peopletools8.56
OracleUtilities Framework4.3.0.6.0
OracleWebcenter Portal11.1.1.9.0
OracleCommunications Messaging Server8.0.2

References

FAQ

What is CVE-2020-28052?

CVE-2020-28052 is a vulnerability with a CVSS score of 8.1 (HIGH). An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect pass...

How severe is CVE-2020-28052?

CVE-2020-28052 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28052?

Check the references section above for vendor advisories and patch information. Affected products include: Bouncycastle Bc-Java, Apache Karaf, Oracle Banking Corporate Lending Process Management, Oracle Banking Credit Facilities Process Management, Oracle Banking Extensibility Workbench.