Vulnerabilities > CVE-2020-28052

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
bouncycastle
apache
oracle

Summary

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Vulnerable Configurations

Part Description Count
Application
Bouncycastle
2
Application
Apache
1
Application
Oracle
56
OS
Oracle
2

References