CVE-2018-1000180 - Use of a Broken or Risky Cryptographic Algorithm

Severity

50%

Complexity

99%

Confidentiality

48%

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

CVSS 3.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).

Demo Examples

Use of a Broken or Risky Cryptographic Algorithm

CWE-327

These code examples use the Data Encryption Standard (DES).


               
EVP_des_ecb();

               
des.initEncrypt(key2);

               
}
return $encryptedPassword;

Once considered a strong algorithm, DES now regarded as insufficient for many applications. It has been replaced by Advanced Encryption Standard (AES).

Overview

First reported 6 years ago

2018-06-05 13:29:00

Last updated 5 years ago

2019-10-03 00:03:00

Affected Software

Debian Linux 9.0

9.0

Oracle API Gateway 11.1.2.4.0

11.1.2.4.0

Oracle Business Process Management Suite 11.1.1.9.0

11.1.1.9.0

Oracle Business Process Management Suite 12.1.3.0.0

12.1.3.0.0

Oracle Business Process Management Suite 12.2.1.3.0

12.2.1.3.0

Oracle Business Transaction Management 12.1.0

12.1.0

Oracle Communications Application Session Controller 3.7.1

3.7.1

Oracle Communications Application Session Controller 3.8.0

3.8.0

Oracle Enterprise Repository 12.1.3.0.0

12.1.3.0.0

Oracle Managed File Transfer 12.1.3.0.0

12.1.3.0.0

Oracle Managed File Transfer 12.2.1.3.0

12.2.1.3.0

Oracle PeopleSoft Enterprise PeopleTools 8.55

8.55

Oracle PeopleSoft Enterprise PeopleTools 8.56

8.56

Oracle PeopleSoft Enterprise PeopleTools 8.57

8.57

Oracle Retail Xstore Point Of Service 7.0

7.0

Oracle Retail Xstore Point Of Service 7.1

7.1

Oracle SOA Suite 12.1.3.0.0

12.1.3.0.0

Oracle SOA Suite 12.2.1.3.0

12.2.1.3.0

Oracle WebCenter Portal 11.1.1.9.0

11.1.1.9.0

Oracle WebCenter Portal 12.2.1.3.0

12.2.1.3.0

Oracle Weblogic Server 12.1.3.0.0

12.1.3.0.0

Red Hat Virtualization 4.0

4.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.