RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
Conclusion & alert: CVE-2019-3740 is rated Moderate Risk (53.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.24%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 1.07% | 1.24% | +0.17% |
| 2 | 2025-11-18 | 1.18% | 1.07% | -0.11% |
| 3 | 2025-04-26 | — | 1.18% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 6.5 | 3.0 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| dell | bsafe_cert-j | <= 6.2.4 | cpe:2.3:a:dell:bsafe_cert-j:*:*:*:*:*:*:*:* |
| dell | bsafe_crypto-j | < 6.2.5 | cpe:2.3:a:dell:bsafe_crypto-j:*:*:*:*:*:*:*:* |
| dell | bsafe_ssl-j | <= 6.2.4.1 | cpe:2.3:a:dell:bsafe_ssl-j:*:*:*:*:*:*:*:* |
| oracle | application_performance_management | 13.3.0.0 | cpe:2.3:a:oracle:application_performance_management:13.3.0.0:*:*:*:*:*:*:* |
| oracle | application_performance_management | 13.4.0.0 | cpe:2.3:a:oracle:application_performance_management:13.4.0.0:*:*:*:*:*:*:* |
| oracle | communications_network_integrity | 7.3.2 | cpe:2.3:a:oracle:communications_network_integrity:7.3.2:*:*:*:*:*:*:* |
| oracle | communications_network_integrity | 7.3.5 | cpe:2.3:a:oracle:communications_network_integrity:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_network_integrity | 7.3.6 | cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.2 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.2:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.4 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.5 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.0 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.1 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* |
| oracle | database | 12.1.0.2 | cpe:2.3:a:oracle:database:12.1.0.2:*:*:*:enterprise:*:*:* |
| oracle | database | 12.2.0.1 | cpe:2.3:a:oracle:database:12.2.0.1:*:*:*:enterprise:*:*:* |
| oracle | database | 18c | cpe:2.3:a:oracle:database:18c:*:*:*:enterprise:*:*:* |
| oracle | database | 19c | cpe:2.3:a:oracle:database:19c:*:*:*:enterprise:*:*:* |
| oracle | global_lifecycle_management_opatch | < 12.2.0.1.22 | cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* |
| oracle | goldengate | < 19.1.0.0.0.210420 | cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:* |
| oracle | retail_assortment_planning | 15.0.3.0 | cpe:2.3:a:oracle:retail_assortment_planning:15.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_assortment_planning | 16.0.3.0 | cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 14.1 | cpe:2.3:a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 15.0 | cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 16.0 | cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 14.1.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 15.0 | cpe:2.3:a:oracle:retail_predictive_application_server:15.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 15.0.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 16.0.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 14.1 | cpe:2.3:a:oracle:retail_service_backbone:14.1:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 15.0 | cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 16.0 | cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:* |
| oracle | retail_store_inventory_management | 14.0.4 | cpe:2.3:a:oracle:retail_store_inventory_management:14.0.4:*:*:*:*:*:*:* |
| oracle | retail_store_inventory_management | 14.1.3 | cpe:2.3:a:oracle:retail_store_inventory_management:14.1.3:*:*:*:*:*:*:* |
| oracle | retail_store_inventory_management | 15.0.3 | cpe:2.3:a:oracle:retail_store_inventory_management:15.0.3:*:*:*:*:*:*:* |
| oracle | retail_store_inventory_management | 16.0.3 | cpe:2.3:a:oracle:retail_store_inventory_management:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 15.0.3 | cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0.5 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.5:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0.3 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 18.0.2 | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.2:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 19.0.1 | cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.1:*:*:*:*:*:*:* |
| oracle | storagetek_acsls | 8.5.1 | cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:* |
| oracle | storagetek_tape_analytics_sw_tool | 2.3 | cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3:*:*:*:*:*:*:* |
| oracle | weblogic_server | 10.3.6.0.0 | cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.1.3.0.0 | cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.3.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.4.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 14.1.1.0.0 | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.dell.com/support/security/en-us/details/DOC-106556/DSA-2019-094-RSA-BSAFE®%3B-Crypto-J-Multiple-Security-Vulnerabilities | |
| https://www.oracle.com//security-alerts/cpujul2021.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuApr2021.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2020.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2021.html | Patch Third Party Advisory |