RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bsafe_cert-j | Dell | * | 6.2.4 (including) |
Bsafe_crypto-j | Dell | * | 6.2.5 (excluding) |
Bsafe_ssl-j | Dell | * | 6.2.4.1 (including) |