Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2019-3739 Details
Description
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | [email protected] |
| CWE-310 | Cryptographic Issues | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell bsafe cert-j | <= 6.2.4 |
CPE
Remediation
| |
| dell bsafe crypto-j | < 6.2.5 |
CPE
Remediation
| |
| dell bsafe ssl-j | <= 6.2.4.1 |
CPE
Remediation
| |
| oracle application performance management | 13.3.0.0 13.4.0.0 |
CPE
Remediation
| |
| oracle communications network integrity | 7.3.2 7.3.5 7.3.6 |
CPE
Remediation
| |
| oracle database | 12.1.0.2 12.2.0.1 18c 19c |
CPE
Remediation
| |
| oracle goldengate | < 19.1.0.0.0.210420 |
CPE
Remediation
| |
| oracle retail assortment planning | 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail integration bus | 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail predictive application server | 14.1.3.0 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail service backbone | 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail store inventory management | 14.0.4 14.1.3 15.0.3 16.0.3 |
CPE
Remediation
| |
| oracle retail xstore point of service | 15.0.3 16.0.5 17.0.3 18.0.2 19.0.1 |
CPE
Remediation
| |
| oracle storagetek acsls | 8.5.1 |
CPE
Remediation
| |
| oracle storagetek tape analytics sw tool | 2.3 |
CPE
Remediation
| |
| oracle weblogic server | 10.3.6.0.0 12.2.1.3.0 12.2.1.4.0 14.1.1.0.0 |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jun 13, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Dec 9, 2021 | CPE Deprecation Remap | [email protected] |
| Dec 6, 2021 | Modified Analysis | [email protected] |
| Nov 30, 2021 | CPE Deprecation Remap | [email protected] |
| Nov 8, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 20, 2019 | Initial Analysis | [email protected] |