Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000352

 

Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000352

Published: February 5, 2024


Vulnerability identifier: #VU86062
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1000352
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the system.

The vulnerability exists due to ECIES implementation allowed the use of ECB mode. A remote attacker can trigger the vulnerability to bypass security restrictions and escalate privileges on the system.



Affected software

Bouncy Castle for Java
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Sterling File Gateway
Fuse

How to mitigate CVE-2016-1000352

Install updates from vendor's website.

Bouncy Castle for Java - update to 1.56
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins