RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041614 | third party advisory vdb entry |
https://seclists.org/fulldisclosure/2018/Sep/7 | third party advisory mailing list |