← Back to CVE List

CVE-2017-13098

Published: 2017-12-13T01:29Z
Last Modified: 2024-11-21T03:10Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT." > MITRE Terms of Use apply – see LICENSE‑MITRE.txt