Description
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4072-1 | bouncycastle security update |
Github GHSA |
GHSA-wrwf-pmmj-w989 | Observable Discrepancy in BouncyCastle |
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-09-16T18:39:22.646Z
Reserved: 2017-08-22T00:00:00.000Z
Link: CVE-2017-13098
No data.
Status : Modified
Published: 2017-12-13T01:29:00.280
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-13098
OpenCVE Enrichment
No data.
Debian DSA
Github GHSA