Vulnerability Name:

CVE-2020-15522 (CCN-202188)

Assigned:2020-07-04
Published:2020-07-04
Updated:2021-06-22
Summary:Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-362
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-15522

Source: XF
Type: UNKNOWN
bouncycastle-cve202015522-info-disc(202188)

Source: MISC
Type: Third Party Advisory
https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522

Source: CCN
Type: BC Java GIT Repository
CVE 2020 15522

Source: MISC
Type: Third Party Advisory
https://github.com/bcgit/bc-java/wiki/CVE-2020-15522

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20210622-0007/

Source: MISC
Type: Release Notes, Vendor Advisory
https://www.bouncycastle.org/releasenotes.html

Source: CCN
Type: IBM Security Bulletin 6485147 (Watson Machine Learning Accelerator)
A vulnerability in Bouncy Castle affect IBM Watson Machine Learning Accelerator

Source: CCN
Type: IBM Security Bulletin 6570915 (Data Risk Manager)
IBM Data Risk Manager is affected by multiple vulnerabilities including a remote code execution in Spring Framework (CVE-2022-22965)

Source: CCN
Type: IBM Security Bulletin 6598793 (Robotic Process Automation)
IBM Robotic Process Automation may be affected by multiple vulnerabilities in open source components (CVE-2019-0820, CVE-2020-15522, CVE-2021-43569)

Source: CCN
Type: IBM Security Bulletin 6615289 (Planning Analytics Workspace)
IBM Planning Analytics Workspace is affected by multiple vulnerabilities (CVE-2022-22968, CVE-2022-24785, CVE-2017-18214, CVE-2016-4055, CVE-2018-1000613, CVE-2020-15522, CVE-2018-1000180, CVE-2020-26939, CVE-2022-22314)

Source: CCN
Type: IBM Security Bulletin 6829593 (Sterling File Gateway)
IBM Sterling File Gateway is vulnerable to multiple issues due to Bouncy Castle

Source: CCN
Type: IBM Security Bulletin 6831855 (QRadar SIEM)
IBM QRadar SIEM is vulnerable to Using Components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6856465 (PowerSC)
PowerSC is vulnerable to information disclosure due to Bouncy Castle (CVE-2020-15522)

Source: CCN
Type: IBM Security Bulletin 7005485 (Cloud Pak for Network Automation)
Cloud Pak for Network Automation 2.5.0 fixes multiple security vulnerabilities

Vulnerable Configuration:Configuration 1:
  • cpe:/a:bouncycastle:bc-csharp:*:*:*:*:*:*:*:* (Version < 1.8.7)
  • OR cpe:/a:bouncycastle:bouncy_castle_fips_.net_api:*:*:*:*:*:*:*:* (Version < 1.0.1.1)
  • OR cpe:/a:bouncycastle:legion-of-the-bouncy-castle-fips-java-api:*:*:*:*:*:*:*:* (Version < 1.0.1.2)
  • OR cpe:/a:bouncycastle:legion-of-the-bouncy-castle-fips-java-api:*:*:*:*:*:*:*:* (Version >= 1.0.2 and < 1.0.2.1)
  • OR cpe:/a:bouncycastle:the_bouncy_castle_crypto_package_for_java:*:*:*:*:*:*:*:* (Version < 1.66)

  • Configuration CCN 1:
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:sterling_file_gateway:6.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:sterling_file_gateway:6.1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:planning_analytics_workspace:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7993
    P
    bouncycastle-1.72-150200.3.12.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:3368
    P
    squashfs-4.3-6.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94998
    P
    bouncycastle-1.64-3.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94897
    P
    firewall-applet-0.9.3-150400.7.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6075
    P
    Security update for the Linux Kernel (Important)
    2022-06-20
    oval:org.opensuse.security:def:95305
    P
    Security update for MozillaFirefox (Important)
    2022-06-02
    oval:org.opensuse.security:def:102018
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2022-03-01
    oval:org.opensuse.security:def:101610
    P
    Security update for json-c (Important)
    2022-01-25
    oval:org.opensuse.security:def:112022
    P
    bouncycastle-1.68-3.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105578
    P
    bouncycastle-1.68-3.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:4488
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 12 SP5) (Important)
    2021-09-16
    oval:org.opensuse.security:def:111605
    P
    Security update for bouncycastle (Moderate)
    2021-07-10
    oval:org.opensuse.security:def:111470
    P
    Security update for bouncycastle (Moderate)
    2021-06-29
    oval:org.opensuse.security:def:76232
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:97141
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:67164
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:74645
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:65577
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:4558
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:117790
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:74715
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:108276
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:101785
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:65647
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:5757
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:75914
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:108684
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:66846
    P
    Security update for bouncycastle (Moderate)
    2021-06-25
    BACK
    bouncycastle bc-csharp *
    bouncycastle bouncy castle fips .net api *
    bouncycastle legion-of-the-bouncy-castle-fips-java-api *
    bouncycastle legion-of-the-bouncy-castle-fips-java-api *
    bouncycastle the bouncy castle crypto package for java *
    ibm qradar security information and event manager 7.4 -
    ibm sterling file gateway 6.0.0.0
    ibm sterling file gateway 6.1.0.0
    ibm planning analytics workspace 2.0
    ibm robotic process automation 21.0.1