Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2018-1000180 Details
Description
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bouncycastle bc-java | >= 1.54, <= 1.59 |
CPE
Remediation
| |
| bouncycastle fips java api | <= 1.0.1 |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| oracle api gateway | 11.1.2.4.0 |
CPE
Remediation
| |
| oracle business process management suite | 11.1.1.9.0 12.1.3.0.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle business transaction management | 12.1.0 |
CPE
Remediation
| |
| oracle communications application session controller | 3.7.1 3.8.0 |
CPE
Remediation
| |
| oracle communications converged application server | < 7.0.0.1 |
CPE
Remediation
| |
| oracle communications webrtc session controller | < 7.2 |
CPE
Remediation
| |
| oracle enterprise repository | 12.1.3.0.0 |
CPE
Remediation
| |
| oracle managed file transfer | 12.1.3.0.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.55 8.56 8.57 |
CPE
Remediation
| |
| oracle retail convenience and fuel pos software | 2.8.1 |
CPE
Remediation
| |
| oracle retail xstore point of service | 7.0 7.1 |
CPE
Remediation
| |
| oracle soa suite | 12.1.3.0.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle webcenter portal | 11.1.1.9.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle weblogic server | 12.1.3.0.0 |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| redhat virtualization | 4.2 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 7.1.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 12, 2025 | CPE Deprecation Remap | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Oct 15, 2020 | CPE Deprecation Remap | [email protected] |
| Oct 12, 2020 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Nov 12, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| Apr 26, 2019 | Modified Analysis | [email protected] |
| Apr 24, 2019 | CVE Modified | [email protected] |
| Apr 23, 2019 | CVE Modified | [email protected] |
| Apr 17, 2019 | CVE Modified | [email protected] |
| Feb 5, 2019 | CVE Modified | [email protected] |
| Jan 16, 2019 | CVE Modified | [email protected] |
| Sep 12, 2018 | CVE Modified | [email protected] |
| Sep 5, 2018 | CVE Modified | [email protected] |
| Aug 16, 2018 | CVE Modified | [email protected] |
| Aug 2, 2018 | Initial Analysis | [email protected] |
| Jun 24, 2018 | CVE Modified | [email protected] |