We found results for “”
CVE-2007-6721
Good to know:
Date: March 29, 2009
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
Language: Java
Severity Score
Related Resources (12)
Severity Score
Weakness Type (CWE)
Insufficient Information
NVD-CWE-noinfoObservable Discrepancy
CWE-203Top Fix
Upgrade Version
Upgrade to version bouncycastle:bcprov-jdk15:136,org.bouncycastle:bcprov-jdk15:1.38
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | COMPLETE |
Integrity (I): | COMPLETE |
Availability (A): | COMPLETE |
Additional information: |