Lucene search

K
ibmIBMF4AD67856A898B69A096AB9AB6B4F338381B13CD38018277B12F1DD7EEB59C84
HistoryJan 28, 2021 - 6:38 p.m.

Security Bulletin: Bouncy Castle Vulnerability

2021-01-2818:38:52
www.ibm.com
12

0.001 Low

EPSS

Percentile

36.2%

Summary

ViewONE has a bundled version of Bouncy Castle containing a known security issue.

Vulnerability Details

CVEID:CVE-2020-26939
**DESCRIPTION:**Legion of the Bouncy Castle BC and Legion of the Bouncy Castle BC-FJA could allow a remote attacker to obtain sensitive information, caused by observable differences in behavior to rrror inputs in org.bouncycastle.crypto.encodings.OAEPEncoding. By using the OAEP Decoder to send invalid ciphertext that decrypts to a short payload, a remote attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191108 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Daeja ViewONE Professional, Standard & Virtual 5.0CD

Remediation/Fixes

Bouncy Castle library bundled with ViewONE has been updated for release 5.0.9 ifix 2 and 5.0.8 ifix 7.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm daeja viewone virtualeq5.0

0.001 Low

EPSS

Percentile

36.2%

Related for F4AD67856A898B69A096AB9AB6B4F338381B13CD38018277B12F1DD7EEB59C84