Information Exposure Through Timing Discrepancy in Bouncy Castle for Java - CVE-2020-15522
Published: July 20, 2021
Vulnerability identifier: #VU55035
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15522
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The
vulnerability exists due to a timing issue within the EC math library. A remote attacker who can observe timing information for the generation of multiple deterministic ECDSA signatures is able to reconstruct the private key used for encryption.
Affected software
Bouncy Castle for Java
IBM Watson Machine Learning Accelerator
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
SUSE Linux Enterprise Module for Development Tools
openEuler
PowerSC
IBM Robotic Process Automation
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Observability with Instana
bouncycastle
bouncycastle-pg
IBM Sterling File Gateway
Fuse
IBM Watson Machine Learning Accelerator
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
SUSE Linux Enterprise Module for Development Tools
openEuler
PowerSC
IBM Robotic Process Automation
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Observability with Instana
bouncycastle
bouncycastle-pg
IBM Sterling File Gateway
Fuse
How to mitigate CVE-2020-15522
Install updates from vendor's website.
Bouncy Castle for Java - update to 1.66
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Robotic Process Automation - update to 21.0.1.5
Netcool Operations Insight - update to 1.6.9
bouncycastle - update to 1.61-5
bouncycastle-pg - update to 1.64-3.3.1
bouncycastle - update to 1.64-3.3.1
PowerSC - update to 2.1.0.4
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3, 9.1.0
IBM Observability with Instana - update to 269
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Robotic Process Automation - update to 21.0.1.5
Netcool Operations Insight - update to 1.6.9
bouncycastle - update to 1.61-5
bouncycastle-pg - update to 1.64-3.3.1
bouncycastle - update to 1.64-3.3.1
PowerSC - update to 2.1.0.4
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3, 9.1.0
IBM Observability with Instana - update to 269
External References
Related Security Bulletins
- Information disclosure in Bouncy Castle BC Java
- SUSE update for bouncycastle
- Multiple vulnerabilities in IBM Robotic Process Automation
- Information disclosure in IBM Watson Machine Learning Accelerator
- Multiple vulnerabilities in IBM QRadar SIEM
- Information exposure through timing discrepancy in IBM PowerSC
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Application Performance Management products
- openEuler update for bouncycastle
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in IBM Sterling File Gateway
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)