CVE-2018-1000613: Bouncycastle Bc-Java
Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
Affected products
- Bouncycastle Bc-Java: from 1.58, before 1.60 (fixed in 1.60)
- Netapp Oncommand Workflow Automation: affected versions not specified
- Opensuse Leap: version 15.1 only
- Oracle API Gateway: version 11.1.2.4.0 only
- Oracle Banking Platform: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
- Oracle Business Process Management Suite: version 11.1.1.9.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Oracle Business Transaction Management: version 12.1.0 only
- Oracle Communications Application Session Controller: version 3.7.1 only; version 3.8.0 only
- Oracle Communications Converged Application Server: before 7.0.0.1 (fixed in 7.0.0.1); version 7.0.0.1 only
- Oracle Communications Convergence: version 3.0.2 only
- Oracle Communications Diameter Signaling Router: version 8.0.0 only; version 8.1 only; version 8.2 only; version 8.2.1 only
- Oracle Communications WebRTC Session Controller: before 7.2 (fixed in 7.2); version 7.2 only
- Oracle Data Integrator: version 12.2.1.3.0 only
- Oracle Enterprise Manager Base Platform: version 12.1.0.5.0 only; version 13.2.0.0 only; version 13.3.0.0 only
- Oracle Enterprise Manager For Fusion Middleware: version 13.2.0.0 only; version 13.3.0.0 only
- Oracle Enterprise Repository: version 11.1.1.7.0 only; version 12.1.3.0.0 only
- Oracle Managed File Transfer: version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Oracle PeopleSoft Enterprise PeopleTools: version 8.55 only; version 8.56 only; version 8.57 only
- Oracle Retail Convenience And Fuel Pos Software: version 2.8.1 only
- Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
- Oracle Soa Suite: version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Oracle Utilities Network Management System: version 1.12.0.3 only; version 2.3.0.0 only; version 2.3.0.1 only; version 2.3.0.2 only
- Oracle Webcenter Portal: version 11.1.1.9.0 only; version 12.2.1.3.0 only
- Oracle WebLogic Server: version 12.2.1.3 only
Published 2018-07-09. Last modified 2026-06-17.