RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Missing Cpu Apr 2021 | — | Apply the April 2021 Critical Patch Update (CPU) for Oracle Database | Apr 21, 2021 | Sep 18, 2019 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 32697788 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 32697734 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 32403651 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 32698246 for version 12.2.1.4.0. | Apr 20, 2021 | Sep 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub