47
CVE-2020-28052
PoC —CVSS 3.1
8.1 high
EPSS
7%p94
Published
()
Modified
Description
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
- Vendors
- bouncycastleapacheoracle
- Products
- bc-java, karaf, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking supply chain finance, banking virtual account management, blockchain platform, commerce guided search, communications application session controller, communications cloud native core network slice selection function, communications convergence
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H