Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000352
Published: February 5, 2024
Vulnerability identifier: #VU86062
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1000352
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to ECIES implementation allowed the use of ECB mode. A remote attacker can trigger the vulnerability to bypass security restrictions and escalate privileges on the system.
Affected software
Bouncy Castle for Java
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Sterling File Gateway
Fuse
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Sterling File Gateway
Fuse
How to mitigate CVE-2016-1000352
Install updates from vendor's website.
Bouncy Castle for Java - update to 1.56
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14