A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-2315 A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T17:41:55.640Z

Reserved: 2017-06-28T00:00:00

Link: CVE-2017-10668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-06-30T12:29:00.213

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-10668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.