Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-17359
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.13
EPSS Ranking
93.7%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
https://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r4d475dcaf4f57115fa57d8e06c3823ca398b35468429e7946ebaefdc%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r79b6a6aa0dd1aeb57bd253d94794bc96f1ec005953c4bd5414cc0db0%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r8ecb5b76347f84b6e3c693f980dbbead88c25f77b815053c4e6f2c30%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r91b07985b1307390a58c5b9707f0b28ef8e9c9e1c86670459f20d601%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/re60f980c092ada4bfe236dcfef8b6ca3e8f3b150fc0f51b8cc13d59d%40%3Ccommits.tomee.apache.org%3E
https://security.netapp.com/advisory/ntap-20191024-0006/
https://www.bouncycastle.org/latest_releases.html
https://www.bouncycastle.org/releasenotes.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r4d475dcaf4f57115fa57d8e06c3823ca398b35468429e7946ebaefdc%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r79b6a6aa0dd1aeb57bd253d94794bc96f1ec005953c4bd5414cc0db0%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r8ecb5b76347f84b6e3c693f980dbbead88c25f77b815053c4e6f2c30%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r91b07985b1307390a58c5b9707f0b28ef8e9c9e1c86670459f20d601%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/re60f980c092ada4bfe236dcfef8b6ca3e8f3b150fc0f51b8cc13d59d%40%3Ccommits.tomee.apache.org%3E
https://security.netapp.com/advisory/ntap-20191024-0006/
https://www.bouncycastle.org/latest_releases.html
https://www.bouncycastle.org/releasenotes.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
Products affected by CVE-2019-17359
Apache
»
Tomee
»
Version:
7.0.7
cpe:2.3:a:apache:tomee:7.0.7
Apache
»
Tomee
»
Version:
7.1.2
cpe:2.3:a:apache:tomee:7.1.2
Apache
»
Tomee
»
Version:
8.0.1
cpe:2.3:a:apache:tomee:8.0.1
Bouncycastle
»
Legion-Of-The-Bouncy-Castle-Java-Crytography-Api
»
Version:
1.63
cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.63
Netapp
»
Active Iq Unified Manager
»
Version:
7.3
cpe:2.3:a:netapp:active_iq_unified_manager:7.3
Netapp
»
Active Iq Unified Manager
»
Version:
9.10
cpe:2.3:a:netapp:active_iq_unified_manager:9.10
Netapp
»
Active Iq Unified Manager
»
Version:
9.11p1
cpe:2.3:a:netapp:active_iq_unified_manager:9.11p1
Netapp
»
Active Iq Unified Manager
»
Version:
9.5
cpe:2.3:a:netapp:active_iq_unified_manager:9.5
Netapp
»
Active Iq Unified Manager
»
Version:
9.6
cpe:2.3:a:netapp:active_iq_unified_manager:9.6
Netapp
»
Oncommand Api Services
»
Version:
N/A
cpe:2.3:a:netapp:oncommand_api_services:-
Netapp
»
Oncommand Workflow Automation
»
Version:
N/A
cpe:2.3:a:netapp:oncommand_workflow_automation:-
Netapp
»
Service Level Manager
»
Version:
N/A
cpe:2.3:a:netapp:service_level_manager:-
Oracle
»
Business Process Management Suite
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0
Oracle
»
Business Process Management Suite
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0
Oracle
»
Communications Convergence
»
Version:
3.0.2
cpe:2.3:a:oracle:communications_convergence:3.0.2
Oracle
»
Communications Convergence
»
Version:
3.0.2.1
cpe:2.3:a:oracle:communications_convergence:3.0.2.1
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.0.0
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.0.0.0
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0.0
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.1
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.2
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.2.1
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.1
Oracle
»
Communications Diameter Signaling Router
»
Version:
8.2.2
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.2
Oracle
»
Communications Session Route Manager
»
Version:
8.2.0
cpe:2.3:a:oracle:communications_session_route_manager:8.2.0
Oracle
»
Communications Session Route Manager
»
Version:
8.2.0.0
cpe:2.3:a:oracle:communications_session_route_manager:8.2.0.0
Oracle
»
Communications Session Route Manager
»
Version:
8.2.1
cpe:2.3:a:oracle:communications_session_route_manager:8.2.1
Oracle
»
Communications Session Route Manager
»
Version:
8.2.2
cpe:2.3:a:oracle:communications_session_route_manager:8.2.2
Oracle
»
Data Integrator
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:data_integrator:12.2.1.4.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.0.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.0.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.0.1
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.0.1
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.1.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.1.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.2.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.2.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.3.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.3.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.6.4.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.4.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.7
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.7.0.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.0.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.7.1.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.1.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.7.2.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.2.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.8
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.8.0.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.0.0
Oracle
»
Financial Services Analytical Applications Infrastructure
»
Version:
8.0.9
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.9
Oracle
»
Flexcube Private Banking
»
Version:
12.0.0
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0
Oracle
»
Flexcube Private Banking
»
Version:
12.1.0
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0
Oracle
»
Hospitality Guest Access
»
Version:
4.2.0
cpe:2.3:a:oracle:hospitality_guest_access:4.2.0
Oracle
»
Managed File Transfer
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0
Oracle
»
Managed File Transfer
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0
Oracle
»
Peoplesoft Enterprise Hcm Global Payroll Switzerland
»
Version:
9.2
cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_switzerland:9.2
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.56
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.57
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.58
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58
Oracle
»
Retail Xstore Point Of Service
»
Version:
18.0.1
cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.1
Oracle
»
Soa Suite
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:soa_suite:12.2.1.3.0
Oracle
»
Soa Suite
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:soa_suite:12.2.1.4.0
Oracle
»
Webcenter Portal
»
Version:
11.1.1.9.0
cpe:2.3:a:oracle:webcenter_portal:11.1.1.9.0
Oracle
»
Webcenter Portal
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0
Oracle
»
Webcenter Portal
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0
Oracle
»
Weblogic Server
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0
Oracle
»
Weblogic Server
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved