CVE-2019-3739
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
Published:Sep 18, 2019
Last Modified:Nov 21, 2024
EPS:Sep 18, 2019
EPSS Score:0.01239
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Bsafe Cert-j
Dell
Bsafe Cert-j
Vendor
Dell
Product
Bsafe Crypto-j
Dell
Bsafe Crypto-j
Vendor
Dell
Product
Bsafe Ssl-j
Dell
Bsafe Ssl-j
Vendor
Oracle
Product
Application Performance Management
Oracle
Application Performance Management
Vendor
Oracle
Product
Communications Network Integrity
Oracle
Communications Network Integrity
Vendor
Oracle
Product
Database
Oracle
Database
Vendor
Oracle
Product
Goldengate
Oracle
Goldengate
Vendor
Oracle
Product
Retail Assortment Planning
Oracle
Retail Assortment Planning
Vendor
Oracle
Product
Retail Integration Bus
Oracle
Retail Integration Bus
Vendor
Oracle
Product
Retail Predictive Application Server
Oracle
Retail Predictive Application Server
Vendor
Oracle
Product
Retail Service Backbone
Oracle
Retail Service Backbone
Vendor
Oracle
Product
Retail Store Inventory Management
Oracle
Retail Store Inventory Management
Vendor
Oracle
Product
Retail Xstore Point Of Service
Oracle
Retail Xstore Point Of Service
Vendor
Oracle
Product
Storagetek Acsls
Oracle
Storagetek Acsls
Vendor
Oracle
Product
Storagetek Tape Analytics Sw Tool
Oracle
Storagetek Tape Analytics Sw Tool
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
