CVE-2018-1000180: Bouncycastle Bc-Java

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Affected products

  • Bouncycastle Bc-Java: from 1.54, up to and including 1.59
  • Bouncycastle Fips Java API: up to and including 1.0.1
  • Debian Debian Linux: version 9.0 only
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Oracle API Gateway: version 11.1.2.4.0 only
  • Oracle Business Process Management Suite: version 11.1.1.9.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Business Transaction Management: version 12.1.0 only
  • Oracle Communications Application Session Controller: version 3.7.1 only; version 3.8.0 only
  • Oracle Communications Converged Application Server: before 7.0.0.1 (fixed in 7.0.0.1)
  • Oracle Communications WebRTC Session Controller: before 7.2 (fixed in 7.2)
  • Oracle Enterprise Repository: version 12.1.3.0.0 only
  • Oracle Managed File Transfer: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.55 only; version 8.56 only; version 8.57 only
  • Oracle Retail Convenience And Fuel Pos Software: version 2.8.1 only
  • Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
  • Oracle Soa Suite: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Webcenter Portal: version 11.1.1.9.0 only; version 12.2.1.3.0 only
  • Oracle WebLogic Server: version 12.1.3.0.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.1.0 only
  • Red Hat Virtualization: version 4.2 only

Published 2018-06-05. Last modified 2026-06-17.