The vendor explicitly identifies these products as affected by this CVE.
- bcpg-jdk15on as a component of Red Hat JBoss Enterprise Application Platform 7
- bcpg-jdk15on as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Bouncy Castle for Java. A remote attacker can exploit an OpenPGP (Open Pretty Good Privacy) Cipher Feedback (CFB) quick-check oracle vulnerability. This oracle, active on symmetric and session-key paths, could allow an attacker to gain sensitive information by observing the results of cryptographic operations. This could lead to the disclosure of confidential data.
- Remediation
- Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcpg-fips 1.0.13/2.0.13/2.1.13) once available for the affected product.
