Lucene search

K
cveMitreCVE-2007-6721
HistoryMar 30, 2009 - 1:30 a.m.

CVE-2007-6721

2009-03-3001:30:00
mitre
web.nvd.nist.gov
41
legion of the bouncy castle
java cryptography
api
bleichenbacher vulnerability
rsa cms
nvd
cve-2007-6721

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.006

Percentile

78.9%

The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to “a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes.”

Affected configurations

Nvd
Node
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiRange1.37
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.01
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.02
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.03
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.04
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.05
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.06
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.07
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.08
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.09
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.10
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.11
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.12
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.13
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.14
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.15
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.16
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.17
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.18
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.19
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.20
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.21
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.22
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.23
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.24
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.25
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.26
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.27
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.28
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.29
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.30
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.31
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.32
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.33
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.34
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.35
OR
bouncycastlelegion-of-the-bouncy-castle-java-crytography-apiMatch1.36
AND
bouncycastlebouncy-castle-crypto-packageRange1.35
OR
bouncycastlebouncy-castle-crypto-packageMatch1.0
OR
bouncycastlebouncy-castle-crypto-packageMatch1.01
OR
bouncycastlebouncy-castle-crypto-packageMatch1.02
OR
bouncycastlebouncy-castle-crypto-packageMatch1.03
OR
bouncycastlebouncy-castle-crypto-packageMatch1.3.1
OR
bouncycastlebouncy-castle-crypto-packageMatch1.04
OR
bouncycastlebouncy-castle-crypto-packageMatch1.05
OR
bouncycastlebouncy-castle-crypto-packageMatch1.06
OR
bouncycastlebouncy-castle-crypto-packageMatch1.07
OR
bouncycastlebouncy-castle-crypto-packageMatch1.08
OR
bouncycastlebouncy-castle-crypto-packageMatch1.09
OR
bouncycastlebouncy-castle-crypto-packageMatch1.11
OR
bouncycastlebouncy-castle-crypto-packageMatch1.12
OR
bouncycastlebouncy-castle-crypto-packageMatch1.13
OR
bouncycastlebouncy-castle-crypto-packageMatch1.14
OR
bouncycastlebouncy-castle-crypto-packageMatch1.15
OR
bouncycastlebouncy-castle-crypto-packageMatch1.16
OR
bouncycastlebouncy-castle-crypto-packageMatch1.17
OR
bouncycastlebouncy-castle-crypto-packageMatch1.18
OR
bouncycastlebouncy-castle-crypto-packageMatch1.19
OR
bouncycastlebouncy-castle-crypto-packageMatch1.20
OR
bouncycastlebouncy-castle-crypto-packageMatch1.21
OR
bouncycastlebouncy-castle-crypto-packageMatch1.22
OR
bouncycastlebouncy-castle-crypto-packageMatch1.23
OR
bouncycastlebouncy-castle-crypto-packageMatch1.24
OR
bouncycastlebouncy-castle-crypto-packageMatch1.25
OR
bouncycastlebouncy-castle-crypto-packageMatch1.26
OR
bouncycastlebouncy-castle-crypto-packageMatch1.27
OR
bouncycastlebouncy-castle-crypto-packageMatch1.28
OR
bouncycastlebouncy-castle-crypto-packageMatch1.29
OR
bouncycastlebouncy-castle-crypto-packageMatch1.30
OR
bouncycastlebouncy-castle-crypto-packageMatch1.32
OR
bouncycastlebouncy-castle-crypto-packageMatch1.33
OR
bouncycastlebouncy-castle-crypto-packageMatch1.34
VendorProductVersionCPE
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api*cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.01cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.01:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.02cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.02:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.03cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.03:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.04cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.04:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.05cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.05:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.06cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.06:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.07cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.07:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.08cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.08:*:*:*:*:*:*:*
bouncycastlelegion-of-the-bouncy-castle-java-crytography-api1.09cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.09:*:*:*:*:*:*:*
Rows per page:
1-10 of 721

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.006

Percentile

78.9%