In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
Loading...
Loading...
In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
June 4, 2018
May 12, 2025
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.bouncycastle:bcprov-jdk14 | 1.38 ... 1.55 (13 versions) | 1.56 | — |
| org.bouncycastle:bcprov-jdk15 | 1.32 ... 1.46 (7 versions) | 1.56 | — |
| org.bouncycastle:bcprov-jdk15on | 1.46 ... 1.55 (10 versions) | 1.56 | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2016-1000352
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.