Information Exposure Through Timing Discrepancy in Bouncy Castle for Java - CVE-2020-15522

 

Information Exposure Through Timing Discrepancy in Bouncy Castle for Java - CVE-2020-15522

Published: July 20, 2021


Vulnerability identifier: #VU55035
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15522
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a timing issue within the EC math library. A remote attacker who can observe timing information for the generation of multiple deterministic ECDSA signatures is able to reconstruct the private key used for encryption.


Affected software

Bouncy Castle for Java
IBM Watson Machine Learning Accelerator
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
SUSE Linux Enterprise Module for Development Tools
openEuler
PowerSC
IBM Robotic Process Automation
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Observability with Instana
bouncycastle
bouncycastle-pg
IBM Sterling File Gateway
Fuse

How to mitigate CVE-2020-15522

Install updates from vendor's website.

Bouncy Castle for Java - update to 1.66
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Robotic Process Automation - update to 21.0.1.5
Netcool Operations Insight - update to 1.6.9
bouncycastle - update to 1.61-5
bouncycastle-pg - update to 1.64-3.3.1
bouncycastle - update to 1.64-3.3.1
PowerSC - update to 2.1.0.4
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3, 9.1.0
IBM Observability with Instana - update to 269

External References

Related Security Bulletins