CVE-2018-1000180
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Published:Apr 18, 2018
Last Modified:May 12, 2025
EPS:Jun 5, 2018
EPSS Score:0.00244
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Bouncycastle
Product
Bc-java
Bouncycastle
Bc-java
Vendor
Bouncycastle
Product
Fips Java Api
Bouncycastle
Fips Java Api
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Netapp
Product
Oncommand Workflow Automation
Netapp
Oncommand Workflow Automation
Vendor
Oracle
Product
Api Gateway
Oracle
Api Gateway
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Business Transaction Management
Oracle
Business Transaction Management
Vendor
Oracle
Product
Communications Application Session Controller
Oracle
Communications Application Session Controller
Vendor
Oracle
Product
Communications Converged Application Server
Oracle
Communications Converged Application Server
Vendor
Oracle
Product
Communications Webrtc Session Controller
Oracle
Communications Webrtc Session Controller
Vendor
Oracle
Product
Enterprise Repository
Oracle
Enterprise Repository
Vendor
Oracle
Product
Managed File Transfer
Oracle
Managed File Transfer
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Retail Convenience And Fuel Pos Software
Oracle
Retail Convenience And Fuel Pos Software
Vendor
Oracle
Product
Retail Xstore Point Of Service
Oracle
Retail Xstore Point Of Service
Vendor
Oracle
Product
Soa Suite
Oracle
Soa Suite
Vendor
Oracle
Product
Webcenter Portal
Oracle
Webcenter Portal
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Jboss Single Sign On
Redhat
Jboss Single Sign On
Vendor
Redhat
Product
Openshift Application Runtimes
Redhat
Openshift Application Runtimes
Vendor
Redhat
Product
Virtualization
Redhat
Virtualization
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
