Vulnerability Name:

CVE-2019-17359 (CCN-168581)

Assigned:2019-10-08
Published:2019-10-08
Updated:2022-10-07
Summary:The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-770
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-17359

Source: XF
Type: UNKNOWN
bouncycastle-cve201917359-dos(168581)

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200320 [jira] [Assigned] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200320 [jira] [Commented] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200320 [jira] [Created] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200320 [jira] [Updated] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200519 [jira] [Resolved] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200519 [jira] [Updated] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200322 [jira] [Updated] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[tomee-commits] 20200323 [jira] [Commented] (TOMEE-2788) TomEE plus is affected by CVE-2019-17359 (BDSA-2019-3168) vulnerability

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20191024-0006/

Source: CCN
Type: Bouncy Castle Web site
The Legion of the Bouncy Castle

Source: MISC
Type: Release Notes, Vendor Advisory
https://www.bouncycastle.org/latest_releases.html

Source: MISC
Type: Release Notes, Vendor Advisory
https://www.bouncycastle.org/releasenotes.html

Source: CCN
Type: IBM Security Bulletin 6369607 (App Connect for Manufacturing)
App Connect for Manufacturing 2.0 is affected by vulnerabilities of ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.6 (CVE-2019-17359)

Source: CCN
Type: IBM Security Bulletin 6416391 (Spectrum Symphony)
Multiple vulnerability issues affect IBM Spectrum Symphony 7.3.1

Source: CCN
Type: IBM Security Bulletin 6416393 (Spectrum Conductor)
Multiple vulnerability issues affect IBM Spectrum Conductor 2.5.0

Source: CCN
Type: IBM Security Bulletin 6444781 (Log Analysis)
Vulnerability in Bouncy Castle affect Apache Solr shipped IBM Operations Analytics - Log Analysis Analysis (CVE-2019-17359)

Source: CCN
Type: IBM Security Bulletin 6570915 (Data Risk Manager)
IBM Data Risk Manager is affected by multiple vulnerabilities including a remote code execution in Spring Framework (CVE-2022-22965)

Source: CCN
Type: Oracle CPUApr2020
Oracle Critical Patch Update Advisory - April 2020

Source: N/A
Type: Patch, Third Party Advisory
N/A

Source: CCN
Type: Oracle CPUJan2020
Oracle Critical Patch Update Advisory - January 2020

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html

Source: CCN
Type: Oracle CPUJan2021
Oracle Critical Patch Update Advisory - January 2021

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html

Source: CCN
Type: Oracle CPUJul2020
Oracle Critical Patch Update Advisory - July 2020

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html

Source: CCN
Type: Oracle CPUOct2020
Oracle Critical Patch Update Advisory - October 2020

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.63:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:apache:tomee:7.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomee:7.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomee:8.0.1:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:service_level_manager:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:oncommand_api_services:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* (Version >= 7.3
  • OR cpe:/a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* (Version >= 9.5
  • OR cpe:/a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:* (Version >= 7.3

  • Configuration 4:
  • cpe:/a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* (Version >= 8.2.0 and <= 8.2.2)
  • OR cpe:/a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* (Version >= 8.0.0 and <= 8.2.2)
  • OR cpe:/a:oracle:peoplesoft_enterprise_hcm_global_payroll_switzerland:9.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_convergence:*:*:*:*:*:*:*:* (Version >= 3.0.1.0 and <= 3.0.2.1)
  • OR cpe:/a:oracle:retail_xstore_point_of_service:18.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* (Version >= 8.0.6 and <= 8.0.9)
  • OR cpe:/a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:flexcube_private_banking:12.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:flexcube_private_banking:12.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_xstore_point_of_service:18.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_pt_peopletools:8.58:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:financial_services_analytical_applications_infrastructure:8.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:log_analysis:1.3.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201917359
    V
    CVE-2019-17359
    2023-06-22
    oval:org.opensuse.security:def:7993
    P
    bouncycastle-1.72-150200.3.12.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:3368
    P
    squashfs-4.3-6.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94998
    P
    bouncycastle-1.64-3.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1378
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Important)
    2022-06-06
    oval:org.opensuse.security:def:112022
    P
    bouncycastle-1.68-3.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105578
    P
    bouncycastle-1.68-3.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:101251
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1904
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62993
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72712
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100828
    P
    enscript-1.6.6-1.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:66795
    P
    Security update for python-httplib2 (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:66703
    P
    Security update for slurm_18_08 (Important)
    2020-12-18
    oval:org.opensuse.security:def:72655
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94115
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107494
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1847
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117052
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62936
    P
    bouncycastle-1.64-1.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49819
    P
    bouncycastle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73368
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70046
    P
    fontforge on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70151
    P
    bouncycastle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73486
    P
    bouncycastle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49765
    P
    zlib-devel-32bit on GA media (Moderate)
    2020-12-01
    BACK
    bouncycastle legion-of-the-bouncy-castle-java-crytography-api 1.63
    apache tomee 7.0.7
    apache tomee 7.1.2
    apache tomee 8.0.1
    netapp oncommand workflow automation -
    netapp service level manager -
    netapp oncommand api services -
    netapp active iq unified manager *
    netapp active iq unified manager *
    netapp active iq unified manager *
    oracle flexcube private banking 12.1.0
    oracle flexcube private banking 12.0.0
    oracle peoplesoft enterprise peopletools 8.56
    oracle hospitality guest access 4.2.0
    oracle weblogic server 12.2.1.3.0
    oracle webcenter portal 12.2.1.3.0
    oracle webcenter portal 11.1.1.9.0
    oracle business process management suite 12.2.1.3.0
    oracle soa suite 12.2.1.3.0
    oracle data integrator 12.2.1.4.0
    oracle communications session route manager *
    oracle communications diameter signaling router *
    oracle peoplesoft enterprise hcm global payroll switzerland 9.2
    oracle business process management suite 12.2.1.4.0
    oracle communications convergence *
    oracle retail xstore point of service 18.0.1
    oracle peoplesoft enterprise peopletools 8.57
    oracle peoplesoft enterprise peopletools 8.58
    oracle webcenter portal 12.2.1.4.0
    oracle soa suite 12.2.1.4.0
    oracle managed file transfer 12.2.1.3.0
    oracle managed file transfer 12.2.1.4.0
    oracle financial services analytical applications infrastructure *
    oracle weblogic server 12.2.1.4.0
    oracle weblogic server 12.2.1.3.0
    oracle flexcube private banking 12.0
    oracle flexcube private banking 12.1
    oracle hospitality guest access 4.2.0
    oracle peoplesoft enterprise peopletools 8.56
    oracle webcenter portal 11.1.1.9.0
    oracle webcenter portal 12.2.1.3.0
    oracle soa suite 12.2.1.3.0
    oracle business process management suite 12.2.1.3.0
    oracle peoplesoft enterprise peopletools 8.57
    oracle retail xstore point of service 18.0.1
    oracle webcenter portal 12.2.1.4.0
    oracle managed file transfer 12.2.1.4.0
    oracle peoplesoft enterprise pt peopletools 8.58
    oracle financial services analytical applications infrastructure 8.0.9
    ibm log analysis 1.3.1
    ibm log analysis 1.3.2
    ibm log analysis 1.3.3
    ibm log analysis 1.3.4
    ibm log analysis 1.3.5
    ibm log analysis 1.3.6