{"id":"CVE-2017-13098","aliases":["GHSA-wrwf-pmmj-w989"],"url":"https://o3.security/vulnerability/CVE-2017-13098","summary":"Observable Discrepancy in BouncyCastle","details":"BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as \"ROBOT.\"","published":"2017-12-13T01:29:00.280Z","modified":"2026-08-07T14:48:52.623981Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.bouncycastle:bcprov-jdk15on","fixedVersion":"1.0.3"}],"fix":{"url":"https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5c","label":"bcgit/bc-java@a00b684"},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102195"},{"type":"REPORT","url":"http://www.kb.cert.org/vuls/id/144389"},{"type":"REPORT","url":"https://robotattack.org/"},{"type":"REPORT","url":"https://security.netapp.com/advisory/ntap-20171222-0001/"},{"type":"REPORT","url":"https://www.debian.org/security/2017/dsa-4072"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:52.623981Z"}}