CVE-2020-28052

EUVD-2021-0782
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
bouncycastlebc-java
1.65
bouncycastlebc-java
1.66
apachekaraf
4.3.2
oraclebanking_corporate_lending_process_management
14.2.0
oraclebanking_corporate_lending_process_management
14.3.0
oraclebanking_corporate_lending_process_management
14.5.0
oraclebanking_credit_facilities_process_management
14.2.0
oraclebanking_credit_facilities_process_management
14.3.0
oraclebanking_credit_facilities_process_management
14.5.0
oraclebanking_extensibility_workbench
14.2.0
oraclebanking_extensibility_workbench
14.3.0
oraclebanking_extensibility_workbench
14.5.0
oraclebanking_supply_chain_finance
14.2.0
oraclebanking_supply_chain_finance
14.3.0
oraclebanking_supply_chain_finance
14.5.0
oraclebanking_virtual_account_management
14.2.0
oraclebanking_virtual_account_management
14.3.0
oraclebanking_virtual_account_management
14.5.0
oracleblockchain_platform
𝑥
< 21.1.2
oraclecommerce_guided_search
11.3.2
oraclecommunications_application_session_controller
3.9m0p3:m0p3
oraclecommunications_cloud_native_core_network_slice_selection_function
1.2.1
oraclecommunications_convergence
3.0.2.2.0
oraclecommunications_pricing_design_center
12.0.0.3.0
oraclecommunications_session_report_manager
8.0.0 ≤
𝑥
≤ 8.2.4.0
oraclecommunications_session_route_manager
8.2.0 ≤
𝑥
≤ 8.2.4
oraclejd_edwards_enterpriseone_tools
𝑥
≤ 9.2.5.3
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oracleutilities_framework
4.3.0.6.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2.0
oracleutilities_framework
4.4.0.3.0
oraclewebcenter_portal
11.1.1.9.0
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclecommunications_messaging_server
8.0.2
oraclecommunications_messaging_server
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bookworm
1.72-2
fixed
bullseye
1.68-2
fixed
buster
not-affected
sid
1.77-1
fixed
stretch
not-affected
trixie
1.77-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
bionic
needs-triage
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
needs-triage
References