Comparison using wrong factors in Bouncy Castle for Java - CVE-2020-28052
Published: December 18, 2020 / Updated: January 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to brute-force password hashes.
The vulnerability exists due to comparison error in OpenBSDBCrypt.checkPassword() function in core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java when matching passwords with hashes. A remote attacker can pass an incorrect password that will be accepted as a valid one by the library, bypass authentication process and gain unauthorized access to the application that uses vulnerable version of Bouncy Castle.
Affected software
Oracle Communications Convergence
Oracle Communications Instant Messaging Server
Oracle Communications Application Session Controller
Oracle Blockchain Platform
Oracle Utilities Framework
Oracle Business Intelligence Enterprise Edition
IBM Cloud Pak for Watson AIOps
JBoss Enterprise Application Platform
Fuse
Oracle WebLogic Server
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Tools
Oracle WebCenter Portal
Oracle Commerce Guided Search
Oracle Business Process Management Suite
eap7-h2database (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-wildfly (Red Hat package)
Red Hat Single Sign-On
RSA Authentication Manager
How to mitigate CVE-2020-28052
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.3.6
Fuse - update to 7.8.1
JD Edwards EnterpriseOne Tools - update to 9.2.5.3
eap7-h2database (Red Hat package) - update to 1.4.197-2.redhat_00005.1.ep7.el7
eap7-avro (Red Hat package) - update to 1.7.6-2.redhat_00003.1.ep7.el7
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - update to 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xalan-j2 (Red Hat package) - update to 2.7.1-26.redhat_00015.1.ep7.el7
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
eap7-apache-cxf (Red Hat package) - update to 3.1.16-3.SP1_redhat_00001.1.ep7.el7
eap7-jboss-xnio-base (Red Hat package) - update to 3.5.10-1.Final_redhat_00001.1.ep7.el7
IBM Cloud Pak for Watson AIOps - update to 4.4.0
eap7-wildfly (Red Hat package) - update to 7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat Single Sign-On - update to 7.4.6
RSA Authentication Manager - update to 8.7 Patch 2
Oracle Blockchain Platform - update to 21.1.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Incorrect password hashing algorithm in Bouncy Castle
- Multiple vulnerabilities in JBoss Enterprise Application Platform
- Multiple vulnerabilities in Oracle Utilities Framework
- Multiple vulnerabilities in Oracle Communications Application Session Controller
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Weak password hashing in Red Hat Fuse
- Multiple vulnerabilities in Oracle WebCenter Portal
- Multiple vulnerabilities in Oracle Communications Convergence
- Multiple vulnerabilities in Oracle Blockchain Platform
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Oracle WebLogic Server
- Comparison using wrong factors in Oracle Business Process Management Suite
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
- Multiple vulnerabilities in Red Hat Single Sign-On 7.4
- RSA Authentication Manager update for third-party components