cbcvebase.
CVE-2019-3739
published 2019-09-18

CVE-2019-3739: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
dellbsafe_cert-j<= 6.2.4
dellbsafe_crypto-j< 6.2.56.2.5
dellbsafe_ssl-j<= 6.2.4.1
dellrsa_bsafe_crypto-j
oracleapplication_performance_management
oracleapplication_performance_management
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oracledatabase
oracledatabase
oracledatabase
oracledatabase
oraclegoldengate< 19.1.0.0.0.21042019.1.0.0.0.210420
oracleretail_assortment_planning
oracleretail_assortment_planning
oracleretail_integration_bus
oracleretail_integration_bus
oracleretail_integration_bus
oracleretail_predictive_application_server
oracleretail_predictive_application_server
oracleretail_predictive_application_server
oracleretail_service_backbone
oracleretail_service_backbone
oracleretail_service_backbone