Information disclosure in Bouncy Castle for Java - CVE-2017-13098

 

Information disclosure in Bouncy Castle for Java - CVE-2017-13098

Published: December 22, 2017 / Updated: May 4, 2020


Vulnerability identifier: #VU9750
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13098
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to the application is susceptible to a chosen ciphertext attack when negotiating an RSA key exchange for any TLS cipher suite. A remote attacker can conduct man-in-the-middle attack and decrypt HTTPS traffic or impersonate the HTTPS server.


Affected software

Bouncy Castle for Java
Log Analysis
Opensuse
Fedora
bouncycastle
IBM Sterling File Gateway
CloudLink

How to mitigate CVE-2017-13098

Update to version 1.0.3.

Bouncy Castle for Java - update to 1.59
Log Analysis - update to 1.3.7.2 IF003
bouncycastle - addressed in versions 1.59-1.fc27, 1.59-1.fc28
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
CloudLink - update to 8.0-3.10.5.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins