CVE-2019-17359 - CVE House
Back to Database
Status published High CVE-2019-17359

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java)...

Vulnerability Description

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17359

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

bouncycastle

View all reports →

Affected Software

bc-java, tomee, active iq unified manager, oncommand api services, oncommand workflow automation, service level manager, business process management suite, communications convergence, communications diameter signaling router, communications session route manager, data integrator, financial services analytical applications infrastructure, flexcube private banking, hospitality guest access, managed file transfer, peoplesoft enterprise hcm global payroll switzerland, peoplesoft enterprise peopletools, retail xstore point of service, soa suite, webcenter portal, weblogic server
Vulnerable Versions:
1.63, 7.0.7, 7.1.2, 8.0.1, 7.3, 9.5, 12.2.1.3.0, 12.2.1.4.0, 3.0.1.0, 8.0.0, 8.2.0, 8.0.6, 12.0.0, 12.1.0, 4.2.0, 9.2, 8.56, 8.57, 8.58, 18.0.1, 11.1.1.9.0

Timeline

Official Publish: October 8th, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.