RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bsafe_cert-j | Dell | * | 6.2.4 (including) |
| Bsafe_crypto-j | Dell | * | 6.2.5 (excluding) |
| Bsafe_ssl-j | Dell | * | 6.2.4.1 (including) |