CVE-2019-3739

MEDIUMCVSS 6.5/10EPSS 2.54%

Last modified

CVE-2019-3739 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.. EPSS estimates a 2.54% chance of exploitation in the next 30 days.

Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Probability
2.54%

82.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellBsafe Cert-J<= 6.2.4
DellBsafe Crypto-J< 6.2.5
DellBsafe Ssl-J<= 6.2.4.1
OracleApplication Performance Management13.3.0.0
OracleApplication Performance Management13.4.0.0
OracleCommunications Network Integrity7.3.2
OracleCommunications Network Integrity7.3.5
OracleCommunications Network Integrity7.3.6
OracleDatabase12.1.0.2
OracleDatabase12.2.0.1
OracleDatabase18c
OracleDatabase19c
OracleGoldengate< 19.1.0.0.0.210420
OracleRetail Assortment Planning15.0.3.0
OracleRetail Assortment Planning16.0.3.0
OracleRetail Integration Bus14.1
OracleRetail Integration Bus15.0
OracleRetail Integration Bus16.0
OracleRetail Predictive Application Server14.1.3.0
OracleRetail Predictive Application Server15.0.3.0
OracleRetail Predictive Application Server16.0.3.0
OracleRetail Service Backbone14.1
OracleRetail Service Backbone15.0
OracleRetail Service Backbone16.0
OracleRetail Store Inventory Management14.0.4
OracleRetail Store Inventory Management14.1.3
OracleRetail Store Inventory Management15.0.3
OracleRetail Store Inventory Management16.0.3
OracleRetail Xstore Point Of Service15.0.3
OracleRetail Xstore Point Of Service16.0.5
OracleRetail Xstore Point Of Service17.0.3
OracleRetail Xstore Point Of Service18.0.2
OracleRetail Xstore Point Of Service19.0.1
OracleStoragetek Acsls8.5.1
OracleStoragetek Tape Analytics Sw Tool2.3
OracleWeblogic Server10.3.6.0.0
OracleWeblogic Server12.2.1.3.0
OracleWeblogic Server12.2.1.4.0
OracleWeblogic Server14.1.1.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-3739?
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
How severe is CVE-2019-3739?
CVE-2019-3739 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 2.54% probability of exploitation in the next 30 days.
How do I fix CVE-2019-3739?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-3739?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST