Unknown
CVE-2020-28052
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-28052
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- apache,
- bouncycastle,
- oracle
Products
- banking corporate lending process management 14.2.0,
- banking corporate lending process management 14.3.0,
- banking corporate lending process management 14.5.0,
- banking credit facilities process management 14.2.0,
- banking credit facilities process management 14.3.0,
- banking credit facilities process management 14.5.0,
- banking extensibility workbench 14.2.0,
- banking extensibility workbench 14.3.0,
- banking extensibility workbench 14.5.0,
- banking supply chain finance 14.2.0,
- banking supply chain finance 14.3.0,
- banking supply chain finance 14.5.0,
- banking virtual account management 14.2.0,
- banking virtual account management 14.3.0,
- banking virtual account management 14.5.0,
- blockchain platform,
- commerce guided search 11.3.2,
- communications application session controller 3.9m0p3,
- communications cloud native core network slice selection function 1.2.1,
- communications convergence 3.0.2.2.0,
- communications messaging server 8.0.2,
- communications messaging server 8.1,
- communications pricing design center 12.0.0.3.0,
- communications session report manager,
- communications session route manager,
- jd edwards enterpriseone tools,
- karaf 4.3.2,
- legion-of-the-bouncy-castle-java-crytography-api 1.65,
- legion-of-the-bouncy-castle-java-crytography-api 1.66,
- peoplesoft enterprise peopletools 8.56,
- peoplesoft enterprise peopletools 8.57,
- peoplesoft enterprise peopletools 8.58,
- utilities framework 4.3.0.6.0,
- utilities framework 4.4.0.0.0,
- utilities framework 4.4.0.2.0,
- utilities framework 4.4.0.3.0,
- webcenter portal 11.1.1.9.0,
- webcenter portal 12.2.1.3.0,
- webcenter portal 12.2.1.4.0
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: