// For flags

CVE-2019-17359

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

El analizador ASN.1 en Bouncy Castle Crypto (también se conoce como BC Java) versión 1.63, puede desencadenar un intento de asignación de memoria grande y un error OutOfMemoryError resultante, por medio de datos ASN.1 diseñados. Esto se corrige en la versión 1.64.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-10-08 CVE Reserved
  • 2019-10-08 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (16)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bouncycastle
Search vendor "Bouncycastle"
Legion-of-the-bouncy-castle-java-crytography-api
Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api"
1.63
Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" and version "1.63"
-
Affected
Apache
Search vendor "Apache"
Tomee
Search vendor "Apache" for product "Tomee"
7.0.7
Search vendor "Apache" for product "Tomee" and version "7.0.7"
-
Affected
Apache
Search vendor "Apache"
Tomee
Search vendor "Apache" for product "Tomee"
7.1.2
Search vendor "Apache" for product "Tomee" and version "7.1.2"
-
Affected
Apache
Search vendor "Apache"
Tomee
Search vendor "Apache" for product "Tomee"
8.0.1
Search vendor "Apache" for product "Tomee" and version "8.0.1"
-
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
>= 7.3
Search vendor "Netapp" for product "Active Iq Unified Manager" and version " >= 7.3"
linux
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
>= 7.3
Search vendor "Netapp" for product "Active Iq Unified Manager" and version " >= 7.3"
windows
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
>= 9.5
Search vendor "Netapp" for product "Active Iq Unified Manager" and version " >= 9.5"
vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
Oncommand Api Services
Search vendor "Netapp" for product "Oncommand Api Services"
--
Affected
Netapp
Search vendor "Netapp"
Oncommand Workflow Automation
Search vendor "Netapp" for product "Oncommand Workflow Automation"
--
Affected
Netapp
Search vendor "Netapp"
Service Level Manager
Search vendor "Netapp" for product "Service Level Manager"
--
Affected
Oracle
Search vendor "Oracle"
Business Process Management Suite
Search vendor "Oracle" for product "Business Process Management Suite"
12.2.1.3.0
Search vendor "Oracle" for product "Business Process Management Suite" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Business Process Management Suite
Search vendor "Oracle" for product "Business Process Management Suite"
12.2.1.4.0
Search vendor "Oracle" for product "Business Process Management Suite" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Convergence
Search vendor "Oracle" for product "Communications Convergence"
>= 3.0.1.0 <= 3.0.2.1
Search vendor "Oracle" for product "Communications Convergence" and version " >= 3.0.1.0 <= 3.0.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Route Manager
Search vendor "Oracle" for product "Communications Session Route Manager"
>= 8.2.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.2.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Data Integrator
Search vendor "Oracle" for product "Data Integrator"
12.2.1.4.0
Search vendor "Oracle" for product "Data Integrator" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Analytical Applications Infrastructure
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure"
>= 8.0.6 <= 8.0.9
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6 <= 8.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.0.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.1.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Guest Access
Search vendor "Oracle" for product "Hospitality Guest Access"
4.2.0
Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Managed File Transfer
Search vendor "Oracle" for product "Managed File Transfer"
12.2.1.3.0
Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Managed File Transfer
Search vendor "Oracle" for product "Managed File Transfer"
12.2.1.4.0
Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Hcm Global Payroll Switzerland
Search vendor "Oracle" for product "Peoplesoft Enterprise Hcm Global Payroll Switzerland"
9.2
Search vendor "Oracle" for product "Peoplesoft Enterprise Hcm Global Payroll Switzerland" and version "9.2"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.56
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.56"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.57
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.58
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.58"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
18.0.1
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "18.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Soa Suite
Search vendor "Oracle" for product "Soa Suite"
12.2.1.3.0
Search vendor "Oracle" for product "Soa Suite" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Soa Suite
Search vendor "Oracle" for product "Soa Suite"
12.2.1.4.0
Search vendor "Oracle" for product "Soa Suite" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
11.1.1.9.0
Search vendor "Oracle" for product "Webcenter Portal" and version "11.1.1.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.2.1.3.0
Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.2.1.4.0
Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.4.0"
-
Affected