CVE-2018-1000613

CRITICALCVSS 9.8/10EPSS 4.77%

Last modified

CVE-2018-1000613 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. EPSS estimates a 4.77% chance of exploitation in the next 30 days.

Description

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
4.77%

90.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BouncycastleBc-Java>= 1.58, < 1.60
NetappOncommand Workflow AutomationAll versions
OpensuseLeap15.1
OracleApi Gateway11.1.2.4.0
OracleBanking Platform2.6.0
OracleBanking Platform2.6.1
OracleBanking Platform2.6.2
OracleBusiness Process Management Suite11.1.1.9.0
OracleBusiness Process Management Suite12.1.3.0.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleBusiness Transaction Management12.1.0
OracleCommunications Application Session Controller3.7.1
OracleCommunications Application Session Controller3.8.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Converged Application Server7.0.0.1
OracleCommunications Convergence3.0.2
OracleCommunications Diameter Signaling Router8.0.0
OracleCommunications Diameter Signaling Router8.1
OracleCommunications Diameter Signaling Router8.2
OracleCommunications Diameter Signaling Router8.2.1
OracleCommunications Webrtc Session Controller< 7.2
OracleCommunications Webrtc Session Controller7.2
OracleData Integrator12.2.1.3.0
OracleEnterprise Manager Base Platform12.1.0.5.0
OracleEnterprise Manager Base Platform13.2.0.0
OracleEnterprise Manager Base Platform13.3.0.0
OracleEnterprise Manager For Fusion Middleware13.2.0.0
OracleEnterprise Manager For Fusion Middleware13.3.0.0
OracleEnterprise Repository11.1.1.7.0
OracleEnterprise Repository12.1.3.0.0
OracleManaged File Transfer12.1.3.0.0
OracleManaged File Transfer12.2.1.3.0
OraclePeoplesoft Enterprise Peopletools8.55
OraclePeoplesoft Enterprise Peopletools8.56
OraclePeoplesoft Enterprise Peopletools8.57
OracleRetail Convenience And Fuel Pos Software2.8.1
OracleRetail Xstore Point Of Service7.0
OracleRetail Xstore Point Of Service7.1
OracleSoa Suite12.1.3.0.0
OracleSoa Suite12.2.1.3.0
OracleUtilities Network Management System1.12.0.3
OracleUtilities Network Management System2.3.0.0
OracleUtilities Network Management System2.3.0.1
OracleUtilities Network Management System2.3.0.2
OracleWebcenter Portal11.1.1.9.0
OracleWebcenter Portal12.2.1.3.0
OracleWeblogic Server12.2.1.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1000613?
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
How severe is CVE-2018-1000613?
CVE-2018-1000613 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 4.77% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1000613?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1000613?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST