Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
Published Sep 10, 2019
3.7
LOWCVSS 3.1
EPSS 3.84%
Description
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Affected products
-
- Version Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
JBoss Core Services Apache HTTP Server 2.4.37 SP2
openssl
Fixed · RHSA-2020:1336
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-0:1.6.3-86.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-86.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el7
Fixed · RHSA-2020:1337
Red Hat Enterprise Linux 8
openssl-1:1.1.1c-15.el8
Fixed · RHSA-2020:1840
Red Hat Enterprise Linux 5
openssl
Out of support scope
Red Hat Enterprise Linux 6
openssl
Out of support scope
Red Hat Enterprise Linux 7
openssl
Will not fix
Red Hat Enterprise Linux 8
compat-openssl10
Fix deferred
Red Hat Enterprise Linux 8
mingw-openssl
Fix deferred
Red Hat JBoss Enterprise Application Platform 5
openssl
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
openssl
Out of support scope
Red Hat JBoss Enterprise Web Server 2
openssl
Out of support scope
Red Hat JBoss Web Server 3
openssl
Out of support scope
Red Hat JBoss Web Server 5
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.37 SP2 | openssl | Fixed | RHSA-2020:1336 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-0:1.6.3-86.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-86.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el7 | Fixed | RHSA-2020:1337 |
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1c-15.el8 | Fixed | RHSA-2020:1840 |
| Red Hat Enterprise Linux 5 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
This attack is carried out by sending a large number of messages to be decrypted by the victim. The attacker needs to receive a response from the victim if the decryption was successful or not. Therefore only if the user application compiled with openssl is designed above way, the attack will be viable. Only CMS_decrypt and PKCS7_decrypt functions are affected. Applications compiled with openssl are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.84% (0.03838) | 89.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.34% (0.03338) | 87.03th | v5 (v2026.06.15) |
| Mar 4, 2026 | 1.63% (0.01633) | 81.62th | v4 (v2025.03.14) |
| Mar 1, 2026 | 2.75% (0.02752) | 85.81th | v4 (v2025.03.14) |
| Feb 4, 2026 | 1.63% (0.01633) | 81.53th | v4 (v2025.03.14) |
| Feb 1, 2026 | 2.75% (0.02752) | 85.70th | v4 (v2025.03.14) |
| Jan 18, 2026 | 1.63% (0.01633) | 81.48th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.63% (0.02635) | 84.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.42% (0.01423) | 79.26th | v4 (v2025.03.14) |
| Mar 12, 2025 | 4.61% (0.04612) | 92.64th | v3 (v2023.03.01) |
| Sep 3, 2024 | 3.14% (0.03142) | 91.29th | v3 (v2023.03.01) |
| Jan 4, 2024 | 1.51% (0.01508) | 85.55th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.08% (0.01082) | 82.63th | v3 (v2023.03.01) |
| Aug 17, 2023 | 0.37% (0.00367) | 68.96th | v3 (v2023.03.01) |
| Aug 1, 2023 | 0.32% (0.00321) | 66.67th | v3 (v2023.03.01) |
| Jul 15, 2023 | 0.33% (0.00334) | 67.30th | v3 (v2023.03.01) |
| Jun 30, 2023 | 0.31% (0.00311) | 65.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.26% (0.00260) | 61.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.72% (0.04720) | 89.23th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.72% (0.04720) | 88.14th | v2 (v2022.01.01) |
| Feb 4, 2022 | 35.45% (0.35455) | 96.81th | v2 (v2022.01.01) |
| Feb 3, 2022 | 22.86% (0.22855) | 94.83th | v1 |
| Jan 6, 2022 | 22.86% (0.22855) | 94.77th | v1 |
| Sep 1, 2021 | 6.19% (0.06194) | 89.58th | v1 |
| Jul 31, 2021 | 6.19% (0.06194) | 0.00th | v1 |
| Apr 14, 2021 | 6.00% (0.06005) | 0.00th | v1 |
References (34)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.html x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2019-1563 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1752100 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=08229ad838c50f644d7e928e2eef147b4308ad64 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=631f94db0065c78181ca9ba5546ebc8bb3884b97 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e21f8cf78a125cd3c8c0d1a1a6c8bb0b901f893f x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365 x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-1563
- https://seclists.org/bugtraq/2019/Oct/0 mailing-listx_refsource_BUGTRAQ
- https://seclists.org/bugtraq/2019/Oct/1 mailing-listx_refsource_BUGTRAQ
- https://seclists.org/bugtraq/2019/Sep/25 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/201911-04 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20190919-0002/ x_refsource_CONFIRM
- https://support.f5.com/csp/article/K97324400?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4376-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4376-2/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4504-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-1563
- https://www.debian.org/security/2019/dsa-4539 vendor-advisoryx_refsource_DEBIAN
- https://www.debian.org/security/2019/dsa-4540 vendor-advisoryx_refsource_DEBIAN
- https://www.openssl.org/news/secadv/20190910.txt x_refsource_CONFIRMVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISC
- https://www.tenable.com/security/tns-2019-09 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.