CVE-2018-1000180

UnknownEPSS 3.59%

Last modified

CVE-2018-1000180 is a vulnerability of currently unknown severity. Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.. EPSS estimates a 3.59% chance of exploitation in the next 30 days.

Description

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Metrics

EPSS Probability
3.59%

88.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BouncycastleBc-Java>= 1.54, <= 1.59
BouncycastleFips Java Api<= 1.0.1
DebianDebian Linux9.0
OracleApi Gateway11.1.2.4.0
OracleBusiness Process Management Suite11.1.1.9.0
OracleBusiness Process Management Suite12.1.3.0.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleBusiness Transaction Management12.1.0
OracleCommunications Application Session Controller3.7.1
OracleCommunications Application Session Controller3.8.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Webrtc Session Controller< 7.2
OracleEnterprise Repository12.1.3.0.0
OracleManaged File Transfer12.1.3.0.0
OracleManaged File Transfer12.2.1.3.0
OraclePeoplesoft Enterprise Peopletools8.55
OraclePeoplesoft Enterprise Peopletools8.56
OraclePeoplesoft Enterprise Peopletools8.57
OracleRetail Convenience And Fuel Pos Software2.8.1
OracleRetail Xstore Point Of Service7.0
OracleRetail Xstore Point Of Service7.1
OracleSoa Suite12.1.3.0.0
OracleSoa Suite12.2.1.3.0
OracleWebcenter Portal11.1.1.9.0
OracleWebcenter Portal12.2.1.3.0
OracleWeblogic Server12.1.3.0.0
NetappOncommand Workflow AutomationAll versions
RedhatVirtualization4.2
RedhatJboss Enterprise Application Platform7.1.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1000180?
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
How severe is CVE-2018-1000180?
Severity scoring for CVE-2018-1000180 is pending analysis. The EPSS model estimates a 3.59% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1000180?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1000180?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST