Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-17359

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
apache / tomee 7.0.7 7.0.7.x
apache / tomee 7.1.2 7.1.2.x
apache / tomee 8.0.1 8.0.1.x
netapp / active_iq_unified_manager 7.3 7.3.x
netapp / active_iq_unified_manager 9.5 9.5.x
oracle / flexcube_private_banking 12.1.0 12.1.0.x
oracle / flexcube_private_banking 12.0.0 12.0.0.x
oracle / peoplesoft_enterprise_peopletools 8.56 8.56.x
oracle / hospitality_guest_access 4.2.0 4.2.0.x
oracle / weblogic_server 12.2.1.3.0 12.2.1.3.0.x
oracle / webcenter_portal 12.2.1.3.0 12.2.1.3.0.x
oracle / webcenter_portal 11.1.1.9.0 11.1.1.9.0.x
oracle / business_process_management_suite 12.2.1.3.0 12.2.1.3.0.x
oracle / soa_suite 12.2.1.3.0 12.2.1.3.0.x
oracle / peoplesoft_enterprise_peopletools 8.57 8.57.x
oracle / managed_file_transfer 12.2.1.3.0 12.2.1.3.0.x
oracle / retail_xstore_point_of_service 18.0.1 18.0.1.x
oracle / weblogic_server 12.2.1.4.0 12.2.1.4.0.x
oracle / peoplesoft_enterprise_peopletools 8.58 8.58.x
oracle / webcenter_portal 12.2.1.4.0 12.2.1.4.0.x
oracle / communications_diameter_signaling_router 8.0.0 8.2.2.x
oracle / data_integrator 12.2.1.4.0 12.2.1.4.0.x
oracle / communications_session_route_manager 8.2.0 8.2.2.x
oracle / managed_file_transfer 12.2.1.4.0 12.2.1.4.0.x
oracle / business_process_management_suite 12.2.1.4.0 12.2.1.4.0.x
oracle / financial_services_analytical_applications_infrastructure 8.0.6 8.0.9.x
oracle / peoplesoft_enterprise_hcm_global_payroll_switzerland 9.2 9.2.x
oracle / soa_suite 12.2.1.4.0 12.2.1.4.0.x
oracle / communications_convergence 3.0.1.0 3.0.2.1.x
org.bouncycastle / bcprov-jdk14 1.63 1.63.x
org.bouncycastle / bcprov-jdk14 1.63 1.64
bouncycastle / bc-java 1.63 1.63.x