CVE-2018-1000180

Description

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.244

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1000180,CVE-2018-2902,CVE-2018-3197 are affected in Oracle WebLogic Server 12.1.3.0.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.1.3.0.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation -Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.55Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.55Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.1.0Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle - bcprov-jdk14 1.60Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.2Windows
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle-bcprov-jdk15on 1.60Windows
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle - bcprov-jdk15 1.60Windows
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle - bcprov-jdk14 for Linux 1.60Linux
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle-bcprov-jdk15on for Linux 1.60Linux
Vulnerabilities CVE-2018-1000180 are fixed in BouncyCastle - bcprov-jdk15 for Linux 1.60Linux
Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-1000180)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234