RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2018/Aug/46 | third party advisory mailing list |
https://www.oracle.com/security-alerts/cpuapr2020.html | third party advisory patch |
https://www.oracle.com/security-alerts/cpujul2020.html | third party advisory patch |
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html | third party advisory patch |
https://www.oracle.com/security-alerts/cpujan2020.html | third party advisory patch |
https://www.oracle.com/security-alerts/cpuoct2020.html | third party advisory patch |