native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 0epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher.
This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/R:U/RE:M/U:Green
Affected products
Legion of the Bouncy Castle Inc. · Bouncy Castle for Java