CVE-2018-1000613
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
Published:Mar 3, 2018
Last Modified:May 12, 2025
EPS:Jul 9, 2018
EPSS Score:0.07679
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Bouncycastle
Product
Bc-java
Bouncycastle
Bc-java
Vendor
Netapp
Product
Oncommand Workflow Automation
Netapp
Oncommand Workflow Automation
Vendor
Opensuse
Product
Leap
Opensuse
Leap
Vendor
Oracle
Product
Api Gateway
Oracle
Api Gateway
Vendor
Oracle
Product
Banking Platform
Oracle
Banking Platform
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Business Transaction Management
Oracle
Business Transaction Management
Vendor
Oracle
Product
Communications Application Session Controller
Oracle
Communications Application Session Controller
Vendor
Oracle
Product
Communications Converged Application Server
Oracle
Communications Converged Application Server
Vendor
Oracle
Product
Communications Convergence
Oracle
Communications Convergence
Vendor
Oracle
Product
Communications Diameter Signaling Router
Oracle
Communications Diameter Signaling Router
Vendor
Oracle
Product
Communications Webrtc Session Controller
Oracle
Communications Webrtc Session Controller
Vendor
Oracle
Product
Data Integrator
Oracle
Data Integrator
Vendor
Oracle
Product
Enterprise Manager Base Platform
Oracle
Enterprise Manager Base Platform
Vendor
Oracle
Product
Enterprise Manager For Fusion Middleware
Oracle
Enterprise Manager For Fusion Middleware
Vendor
Oracle
Product
Enterprise Repository
Oracle
Enterprise Repository
Vendor
Oracle
Product
Managed File Transfer
Oracle
Managed File Transfer
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Retail Convenience And Fuel Pos Software
Oracle
Retail Convenience And Fuel Pos Software
Vendor
Oracle
Product
Retail Xstore Point Of Service
Oracle
Retail Xstore Point Of Service
Vendor
Oracle
Product
Soa Suite
Oracle
Soa Suite
Vendor
Oracle
Product
Utilities Network Management System
Oracle
Utilities Network Management System
Vendor
Oracle
Product
Webcenter Portal
Oracle
Webcenter Portal
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
