cbcvebase.
CVE-2019-3738
published 2019-09-18

CVE-2019-3738: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.68%
74.4th percentile
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
dellbsafe_cert-j<= 6.2.4
dellbsafe_crypto-j< 6.2.56.2.5
dellbsafe_ssl-j<= 6.2.4.1
dellrsa_bsafe_crypto-j
mcafeethreat_intelligence_exchange_server
mcafeethreat_intelligence_exchange_server2.0.0 – 2.3.1
oracleapplication_performance_management
oracleapplication_performance_management
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledatabase
oracledatabase
oracledatabase
oracledatabase
oraclegoldengate< 19.1.0.0.0.21042019.1.0.0.0.210420
oraclegoldengate
oracleretail_assortment_planning
oracleretail_assortment_planning
oracleretail_integration_bus

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.