cbcvebase.
CVE-2019-3740
published 2019-09-18

CVE-2019-3740: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
3.75%
88.7th percentile
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
dellbsafe_cert-j<= 6.2.4
dellbsafe_crypto-j< 6.2.56.2.5
dellbsafe_ssl-j<= 6.2.4.1
dellrsa_bsafe_crypto-j
oracleapplication_performance_management
oracleapplication_performance_management
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledatabase
oracledatabase
oracledatabase
oracledatabase
oracleglobal_lifecycle_management_opatch< 12.2.0.1.2212.2.0.1.22
oraclegoldengate< 19.1.0.0.0.21042019.1.0.0.0.210420
oracleretail_assortment_planning
oracleretail_assortment_planning
oracleretail_integration_bus
oracleretail_integration_bus
oracleretail_integration_bus

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.