Resource exhaustion in Cryptacular - CVE-2020-7226

 

Resource exhaustion in Cryptacular - CVE-2020-7226

Published: May 12, 2020


Vulnerability identifier: #VU27702
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7226
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within CiphertextHeader.java in Cryptacular. A remote attacker can trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.


Affected software

Cryptacular
IBM Data Risk Manager
Oracle WebCenter Sites
IBM Qradar SIEM
Oracle WebLogic Server

How to mitigate CVE-2020-7226

Install updates from vendor's website.

Cryptacular - update to 1.2.4
IBM Data Risk Manager - update to 2.0.6.15
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4

External References

Related Security Bulletins