Information disclosure in Bouncy Castle for Java - CVE-2020-26939
Published: November 2, 2020 / Updated: November 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to observable differences in behavior to error inputs within the org.bouncycastle.crypto.encodings.OAEPEncoding component in Legion of the Bouncy Castle BC. A remote attacker can obtain sensitive information about a private exponent by sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder. This causes the application to throw an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
Affected software
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Observability with Instana
IBM Sterling File Gateway
How to mitigate CVE-2020-26939
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3, 9.1.0
IBM Observability with Instana - update to 269
External References
Related Security Bulletins
- Information disclosure in Bouncy Castle
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Sterling File Gateway
- Multiple vulnerabilities in Dell Secure Connect Gateway