Vulnerability Name: CVE-2018-1000180 (CCN-144810) Assigned: 2018-04-18 Published: 2018-04-18 Updated: 2021-06-14 Summary: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N )6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): NoneAvailibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-327 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2018-1000180 Source: CCN Type: Oracle CPUApr2019Oracle Critical Patch Update Advisory - April 2019 Source: CCN Type: Oracle CPUJan2019Oracle Critical Patch Update Advisory - January 2019 Source: CCN Type: Oracle CPUJul2019Oracle Critical Patch Update Advisory - July 2019 Source: BID Type: Third Party Advisory, VDB Entry106567 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2423 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2424 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2425 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2428 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2643 Source: REDHAT Type: Third Party AdvisoryRHSA-2018:2669 Source: REDHAT Type: Third Party AdvisoryRHSA-2019:0877 Source: XF Type: UNKNOWNbouncycastle-cve20181000180-weak-security(144810) Source: CONFIRM Type: Patch, Third Party Advisoryhttps://github.com/bcgit/bc-java/commit/22467b6e8fe19717ecdf201c0cf91bacf04a55ad Source: CONFIRM Type: Patch, Third Party Advisoryhttps://github.com/bcgit/bc-java/commit/73780ac522b7795fc165630aba8d5f5729acc839 Source: MISC Type: UNKNOWNhttps://github.com/bcgit/bc-java/wiki/CVE-2018-1000180 Source: MLIST Type: UNKNOWN[lucene-solr-user] 20190104 Re: SOLR v7 Security Issues Caused Denial of Use - Sonatype Application Composition Report Source: CONFIRM Type: Patch, Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20190204-0003/ Source: CCN Type: Bouncy Castle Web siteRSA Key Generation: computation of iterations for MR Primality Test Source: MISC Type: Third Party Advisoryhttps://www.bountysource.com/issues/58293083-rsa-key-generation-computation-of-iterations-for-mr-primality-test Source: DEBIAN Type: Third Party AdvisoryDSA-4233 Source: CCN Type: IBM Security Bulletin 3011649 (Resilient)Resilient is vulnerable to Using Components with Known Vulnerabilities Source: CCN Type: IBM Security Bulletin 6152121 (License Metric Tool)Multiple vulnerabilities in Bouncy Castle API affect IBM License Metric Tool v9. Source: CCN Type: IBM Security Bulletin 6320835 (Security Guardium Data Encryption)Multiple Vulnerabilities in IBM Guardium Data Encryption (GDE) Source: CCN Type: IBM Security Bulletin 6347588 (Security Guardium) IBM Security Guardium is affected by multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6356449 (QRadar SIEM)Bouncy Castle as used by IBM QRadar SIEM contains multiple vulnerabilities (CVE-2018-1000613, CVE-2017-13098, CVE-2018-1000180) Source: CCN Type: IBM Security Bulletin 6367945 (Sterling B2B Integrator)Multiple Bouncy Castle Vulnerabilities Affect IBM Sterling B2B Integrator Source: CCN Type: IBM Security Bulletin 6444097 (Log Analysis)Multiple vulnerabilities in Bouncy Castle affects Apache Solr shipped with IBM Operations Analytics - Log Analysis Source: CCN Type: IBM Security Bulletin 6496733 (Sterling B2B Integrator)Bouncy Castle Vulnerabilities Affect IBM Sterling B2B Integrator Source: CCN Type: IBM Security Bulletin 6615289 (Planning Analytics Workspace)IBM Planning Analytics Workspace is affected by multiple vulnerabilities (CVE-2022-22968, CVE-2022-24785, CVE-2017-18214, CVE-2016-4055, CVE-2018-1000613, CVE-2020-15522, CVE-2018-1000180, CVE-2020-26939, CVE-2022-22314) Source: CCN Type: IBM Security Bulletin 6829593 (Sterling File Gateway)IBM Sterling File Gateway is vulnerable to multiple issues due to Bouncy Castle Source: CCN Type: Oracle CPUApr2020Oracle Critical Patch Update Advisory - April 2020 Source: N/A Type: UNKNOWNN/A Source: CCN Type: Oracle Critical Patch Update Advisory - April 2021Oracle Critical Patch Update Advisory - April 2021 Source: MISC Type: UNKNOWNhttps://www.oracle.com/security-alerts/cpuApr2021.html Source: MISC Type: UNKNOWNhttps://www.oracle.com/security-alerts/cpuoct2020.html Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Source: CONFIRM Type: Patch, Third Party Advisoryhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html Source: MISC Type: UNKNOWNhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Vulnerable Configuration: Configuration 1 :cpe:/a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:* (Version >= 1.54 and <= 1.59)OR cpe:/a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:* (Version <= 1.0.1) Configuration 2 :cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:* Configuration 3 :cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* OR cpe:/a:oracle:soa_suite:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:11.1.1.9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_webrtc_session_controller:*:*:*:*:*:*:*:* (Version < 7.2) OR cpe:/a:oracle:communications_application_session_controller:3.8.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_application_session_controller:3.7.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_convenience_and_fuel_pos_software:2.8.1:*:*:*:*:*:*:* OR cpe:/a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:* OR cpe:/a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:7.0:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* OR cpe:/a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_converged_application_server:*:*:*:*:*:*:*:* (Version < 7.0.0.1) OR cpe:/a:oracle:managed_file_transfer:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_transaction_management:12.1.0:*:*:*:*:*:*:* Configuration 4 :cpe:/a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:redhat:virtualization:4.2:*:*:*:*:*:*:* Configuration 6 :cpe:/a:redhat:jboss_enterprise_application_platform:7.1.0:*:*:*:*:*:*:* AND cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:bouncycastle:legion-of-the-bouncy-castle:1.54:*:*:*:*:*:*:* OR cpe:/a:bouncycastle:legion-of-the-bouncy-castle:1.59:*:*:*:*:*:*:* AND cpe:/a:ibm:license_metric_tool:9.2:*:*:*:*:*:*:* OR cpe:/a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_webrtc_session_controller:7.1:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:11.1.1.9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:7.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_diameter_signaling_router:8:*:*:*:*:*:*:* OR cpe:/a:oracle:soa_suite:12.1.3.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_application_session_controller:3.7.1:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_convenience_and_fuel_pos_software:2.8.1:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_converged_application_server:7.0:*:*:*:*:*:*:* OR cpe:/a:ibm:sterling_b2b_integrator:6.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:sterling_b2b_integrator:5.2.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_application_session_controller:3.8.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_convergence:3.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:security_guardium:11.0:*:*:*:*:*:*:* OR cpe:/a:ibm:security_guardium:11.1:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_diameter_signaling_router:8.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.1:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.2:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.3:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.4:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.5:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.6:*:*:*:*:*:*:* OR cpe:/a:ibm:security_guardium_data_encryption:3.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:sterling_b2b_integrator:6.0.3.2:*:*:*:standard:*:*:* OR cpe:/a:ibm:sterling_file_gateway:6.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:sterling_b2b_integrator:6.1.0.0:*:*:*:standard:*:*:* OR cpe:/a:ibm:sterling_file_gateway:6.1.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:planning_analytics_workspace:2.0:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
bouncycastle legion-of-the-bouncy-castle-java-crytography-api *
bouncycastle fips java api *
debian debian linux 9.0
oracle peoplesoft enterprise peopletools 8.57
oracle peoplesoft enterprise peopletools 8.55
oracle soa suite 12.1.3.0.0
oracle soa suite 12.2.1.3.0
oracle business process management suite 12.1.3.0.0
oracle business process management suite 12.2.1.3.0
oracle business process management suite 11.1.1.9.0
oracle communications webrtc session controller *
oracle communications application session controller 3.8.0
oracle communications application session controller 3.7.1
oracle retail convenience and fuel pos software 2.8.1
oracle webcenter portal 11.1.1.9.0
oracle retail xstore point of service 7.1
oracle api gateway 11.1.2.4.0
oracle weblogic server 12.1.3.0.0
oracle enterprise repository 12.1.3.0.0
oracle retail xstore point of service 7.0
oracle peoplesoft enterprise peopletools 8.56
oracle webcenter portal 12.2.1.3.0
oracle managed file transfer 12.2.1.3.0
oracle communications converged application server *
oracle managed file transfer 12.1.3.0.0
oracle business transaction management 12.1.0
netapp oncommand workflow automation -
redhat virtualization 4.2
redhat jboss enterprise application platform 7.1.0
redhat enterprise linux 7.0
redhat enterprise linux 6.0
bouncycastle legion-of-the-bouncy-castle 1.54
bouncycastle legion-of-the-bouncy-castle 1.59
ibm license metric tool 9.2
oracle api gateway 11.1.2.4.0
oracle peoplesoft enterprise peopletools 8.55
oracle weblogic server 12.2.1.3.0
oracle communications webrtc session controller 7.1
oracle peoplesoft enterprise peopletools 8.56
oracle business process management suite 11.1.1.9.0
oracle business process management suite 12.1.3.0.0
oracle retail xstore point of service 7.0
oracle retail xstore point of service 7.1
oracle enterprise repository 11.1.1.7.0
oracle enterprise repository 12.1.3.0.0
oracle webcenter portal 11.1.1.9.0
oracle webcenter portal 12.2.1.3.0
ibm qradar security information and event manager 7.3
oracle communications diameter signaling router 8
oracle soa suite 12.1.3.0.0
oracle soa suite 12.2.1.3.0
oracle business process management suite 12.2.1.3.0
oracle communications application session controller 3.7.1
oracle peoplesoft enterprise peopletools 8.57
oracle retail convenience and fuel pos software 2.8.1
oracle communications converged application server 7.0
ibm sterling b2b integrator 6.0.0.0
ibm sterling b2b integrator 5.2.0.0
oracle communications application session controller 3.8.0
oracle communications diameter signaling router 8.1
oracle communications diameter signaling router 8.2
oracle communications convergence 3.0.2
ibm security guardium 11.0
ibm security guardium 11.1
oracle communications diameter signaling router 8.2.1
ibm qradar security information and event manager 7.4 -
ibm log analysis 1.3.1
ibm log analysis 1.3.2
ibm log analysis 1.3.3
ibm log analysis 1.3.4
ibm log analysis 1.3.5
ibm log analysis 1.3.6
ibm security guardium data encryption 3.0.0.2
ibm sterling b2b integrator 6.0.3.2
ibm sterling file gateway 6.0.0.0
ibm sterling b2b integrator 6.1.0.0
ibm sterling file gateway 6.1.0.0
ibm planning analytics workspace 2.0