Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000344
Published: February 5, 2024
Vulnerability identifier: #VU86066
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1000344
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to DHIES implementation allowed the use of ECB mode. A remote attacker can trigger the vulnerability to modify data on the system.
Affected software
Bouncy Castle for Java
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Sterling File Gateway
Fuse
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
IBM Sterling File Gateway
Fuse
How to mitigate CVE-2016-1000344
Install updates from vendor's website.
Bouncy Castle for Java - update to 1.56
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14