#VU9750 Information disclosure in The Bouncy Castle Crypto Package For Java - CVE-2017-13098
Published: December 22, 2017 / Updated: May 4, 2020
The Bouncy Castle Crypto Package For Java
Legion of the Bouncy Castle Inc.
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the application is susceptible to a chosen ciphertext attack when negotiating an RSA key exchange for any TLS cipher suite. A remote attacker can conduct man-in-the-middle attack and decrypt HTTPS traffic or impersonate the HTTPS server.