Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000341
Published: July 5, 2018
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists in Bouncy Castle JCE Provider implementation of DSA signature generation process. The attacker with ability to observe timings for the generation of signatures can gain information about the signature's k value and ultimately the private value as well.
Affected software
IBM Sterling File Gateway
Fuse
IBM Cloud Application Performance Management (APM)
How to mitigate CVE-2016-1000341
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14