Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7056
HistoryJul 16, 2018 - 4:44 a.m.

Remote Code Execution Via Deserialization

2018-07-1604:44:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.006 Low

EPSS

Percentile

77.8%

Legion of the Bouncy Castle Java Cryptography APIs is vulnerable to remote code execution via a deserialization bug. This is due to a lack of class checking in the deserialization of XMSS/XMSS^MT private keys with BDS state information.

References