PT-2019-5681 · Rsa · Rsa Bsafe Crypto-J

Published

2019-09-18

·

Updated

2022-06-07

·

CVE-2019-3740

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions RSA BSAFE Crypto-J versions prior to 6.2.5
Description The issue is related to errors in the use of cryptography, specifically during DSA key generation, which can lead to information exposure through timing discrepancy. A malicious remote attacker could potentially exploit this to recover DSA keys. The vulnerability can be exploited by a remote attacker using specially crafted HTTPS requests, potentially allowing unauthorized access to information.
Recommendations For RSA BSAFE Crypto-J versions prior to 6.2.5, update to version 6.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the DSA key generation functionality until a patch is available. Avoid using the affected cryptography component for sensitive operations until the issue is resolved.

Fix

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04988
CVE-2019-3740

Affected Products

Rsa Bsafe Crypto-J