CVE-2018-1000613

CRITICAL

Bouncy Castle Java Cryptography APIs <1.60 - Unsafe Reflection in XMSS/XMSS^MT Private Key Deserialization

Title source: llm
STIX 2.1

Description

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

Scores

CVSS v3 9.8
EPSS 0.0504
EPSS Percentile 89.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-470
Status published
Products (48)
bouncycastle/bc-java 1.58 - 1.60
netapp/oncommand_workflow_automation
opensuse/leap 15.1
oracle/api_gateway 11.1.2.4.0
oracle/banking_platform 2.6.0
oracle/banking_platform 2.6.1
oracle/banking_platform 2.6.2
oracle/business_process_management_suite 11.1.1.9.0
oracle/business_process_management_suite 12.1.3.0.0
oracle/business_process_management_suite 12.2.1.3.0
... and 38 more
Published Jul 09, 2018
Tracked Since Feb 18, 2026