Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| bouncycastle | bc-java | 1.58 - 1.60 | - |
| netapp | oncommand_workflow_automation | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
47
Affected Products
22
References
bouncycastle / bc-java
| - |
| opensuse | leap | - | - |
| oracle | api_gateway | - | - |
| oracle | banking_platform | - | - |
| oracle | banking_platform | - | - |
| oracle | banking_platform | - | - |
| oracle | business_process_management_suite | - | - |
| oracle | business_process_management_suite | - | - |
| oracle | business_process_management_suite | - | - |
| oracle | business_transaction_management | - | - |
| oracle | communications_application_session_controller | - | - |
| oracle | communications_application_session_controller | - | - |
| oracle | communications_converged_application_server | 7.0.0.1 | - |
| oracle | communications_converged_application_server | - | - |
| oracle | communications_convergence | - | - |
| oracle | communications_diameter_signaling_router | - | - |
| oracle | communications_diameter_signaling_router | - | - |
| oracle | communications_diameter_signaling_router | - | - |
| oracle | communications_diameter_signaling_router | - | - |
| oracle | communications_webrtc_session_controller | 7.2 | - |
| oracle | communications_webrtc_session_controller | - | - |
| oracle | data_integrator | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_for_fusion_middleware | - | - |
| oracle | enterprise_manager_for_fusion_middleware | - | - |
| oracle | enterprise_repository | - | - |
| oracle | enterprise_repository | - | - |
| oracle | managed_file_transfer | - | - |
| oracle | managed_file_transfer | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | retail_convenience_and_fuel_pos_software | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | soa_suite | - | - |
| oracle | soa_suite | - | - |
| oracle | utilities_network_management_system | - | - |
| oracle | utilities_network_management_system | - | - |
| oracle | utilities_network_management_system | - | - |
| oracle | utilities_network_management_system | - | - |
| oracle | webcenter_portal | - | - |
| oracle | webcenter_portal | - | - |
| oracle | weblogic_server | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability
Impact