CVE-2019-3738

MEDIUMCVSS 6.5/10EPSS 1.68%

Last modified

CVE-2019-3738 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.

Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Probability
1.68%

74.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellBsafe Cert-J<= 6.2.4
DellBsafe Crypto-J< 6.2.5
DellBsafe Ssl-J<= 6.2.4.1
McafeeThreat Intelligence Exchange Server>= 2.0.0, <= 2.3.1
McafeeThreat Intelligence Exchange Server3.0.0
OracleApplication Performance Management13.3.0.0
OracleApplication Performance Management13.4.0.0
OracleCommunications Network Integrity7.3.2
OracleCommunications Network Integrity7.3.5
OracleCommunications Network Integrity7.3.6
OracleCommunications Unified Inventory Management7.3.2
OracleCommunications Unified Inventory Management7.3.4
OracleCommunications Unified Inventory Management7.3.5
OracleCommunications Unified Inventory Management7.4.0
OracleCommunications Unified Inventory Management7.4.1
OracleDatabase12.1.0.2
OracleDatabase12.2.0.1
OracleDatabase18c
OracleDatabase19c
OracleGoldengate< 19.1.0.0.0.210420
OracleGoldengate19.1.0.0.0.210420
OracleRetail Assortment Planning15.0.3.0
OracleRetail Assortment Planning16.0.3.0
OracleRetail Integration Bus14.1
OracleRetail Integration Bus15.0
OracleRetail Integration Bus16.0
OracleRetail Predictive Application Server14.1.3.0
OracleRetail Predictive Application Server15.0.3.0
OracleRetail Predictive Application Server16.0.3.0
OracleRetail Service Backbone14.1
OracleRetail Service Backbone15.0
OracleRetail Service Backbone16.0
OracleRetail Store Inventory Management14.0.4
OracleRetail Store Inventory Management14.1.3
OracleRetail Store Inventory Management15.0.3
OracleRetail Store Inventory Management16.0.3
OracleRetail Xstore Point Of Service15.0.3
OracleRetail Xstore Point Of Service16.0.5
OracleRetail Xstore Point Of Service17.0.3
OracleRetail Xstore Point Of Service18.0.2
OracleRetail Xstore Point Of Service19.0.1
OracleStoragetek Tape Analytics Sw Tool2.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-3738?
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
How severe is CVE-2019-3738?
CVE-2019-3738 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.68% probability of exploitation in the next 30 days.
How do I fix CVE-2019-3738?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-3738?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST