CVE-2007-6721

N/A Unknown
Published: March 30, 2009 Modified: April 23, 2026
View on NVD

Description

The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.bouncycastle.org/csharp/
Source: cve@mitre.org
Patch Vendor Advisory
http://www.bouncycastle.org/devmailarchive/msg08195.html
Source: cve@mitre.org
Patch Vendor Advisory
http://www.osvdb.org/50358
Source: cve@mitre.org
http://www.osvdb.org/50359
Source: cve@mitre.org
http://www.osvdb.org/50360
Source: cve@mitre.org
http://www.bouncycastle.org/csharp/
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.bouncycastle.org/devmailarchive/msg08195.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.bouncycastle.org/releasenotes.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/50358
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/50359
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/50360
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.9%
75th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

bouncycastle