Information disclosure in Bouncy Castle for Java - CVE-2017-13098
Published: December 22, 2017 / Updated: May 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the application is susceptible to a chosen ciphertext attack when negotiating an RSA key exchange for any TLS cipher suite. A remote attacker can conduct man-in-the-middle attack and decrypt HTTPS traffic or impersonate the HTTPS server.
Affected software
Log Analysis
Opensuse
Fedora
bouncycastle
IBM Sterling File Gateway
CloudLink
How to mitigate CVE-2017-13098
Log Analysis - update to 1.3.7.2 IF003
bouncycastle - addressed in versions 1.59-1.fc27, 1.59-1.fc28
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
CloudLink - update to 8.0-3.10.5.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Information disclosure in Bouncy Castle
- OpenSUSE Linux update for bouncycastle
- OpenSUSE Linux update for bouncycastle
- IBM Log Analysis update for Bouncy Castle
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in IBM Sterling File Gateway
- Fedora 28 update for bouncycastle
- Fedora 27 update for bouncycastle