CVE-2019-3739Medium· 6.5▾ SunlitRSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to reco…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.5%
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
bsafe_cert-j <= 6.2.4bsafe_crypto-j < 6.2.5bsafe_ssl-j <= 6.2.4.1application_performance_management = 13.3.0.0application_performance_management = 13.4.0.0communications_network_integrity = 7.3.2communications_network_integrity = 7.3.5communications_network_integrity = 7.3.6database = 12.1.0.2database = 12.2.0.1database = 18cdatabase = 19cgoldengate < 19.1.0.0.0.210420retail_assortment_planning = 15.0.3.0retail_assortment_planning = 16.0.3.0retail_integration_bus = 14.1retail_integration_bus = 15.0retail_integration_bus = 16.0retail_predictive_application_server = 14.1.3.0retail_predictive_application_server = 15.0.3.0retail_predictive_application_server = 16.0.3.0retail_service_backbone = 14.1retail_service_backbone = 15.0retail_service_backbone = 16.0retail_store_inventory_management = 14.0.4retail_store_inventory_management = 14.1.3retail_store_inventory_management = 15.0.3retail_store_inventory_management = 16.0.3retail_xstore_point_of_service = 15.0.3retail_xstore_point_of_service = 16.0.5retail_xstore_point_of_service = 17.0.3retail_xstore_point_of_service = 18.0.2retail_xstore_point_of_service = 19.0.1storagetek_acsls = 8.5.1storagetek_tape_analytics_sw_tool = 2.3weblogic_server = 10.3.6.0.0weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0Upgrade past the affected range:
bsafe_crypto-j 6.2.5goldengate 19.1.0.0.0.210420Connected by shared product, vendor, weakness, or advisory.
CVE-2019-3740Medium· 6.5RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation
CVE-2019-1563Low· 3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption …
CVE-2016-0762Medium· 5.9The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist
CVE-2025-10890Critical· 9.1Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page
CVE-2020-3585Medium· 5.3A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…
CVE-2026-86360Critical· 9.6Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability