A security scan may flag the following Bouncy Castle for Java file (bc-fips-1.0.2.4 or older) on Siteminder r12.9 or older Access Gateway Server
<Install_Dir>/CA/secure-proxy/agentframework/java/bc-fips-1.0.2.4.jar
<Install_Dir>/CA/secure-proxy/Tomcat/webapps/affwebservices/WEB-INF/lib/bc-fips-1.0.2.4.jar
<Install_Dir>/CA/secure-proxy/Tomcat/thirdparty/bc-fips-1.0.2.4.jar
<Install_Dir>/CA/secure-proxy/Tomcat/federation_apps/sts/webapps/WEB-INF/lib/bc-fips-1.0.2.4.jar
PRODUCT: Symantec Siteminder
COMPONENT: Access Gateway Server
VERSION: r12.9 and older
OPERATING SYSTEM: Windows and Linux
CVE-2025-8885
DESCRIPTION: Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcprov, bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java.
IMPACTED: Bouncy Castle for Java
BC 1.0 through 1.77
BC-FJA 1.0.0 through 1.0.2.5
BC-FJA 2.0.0 through 2.0.0
REMEDIATED: Bouncy Castle for Java 1.0.2.6
Upgrade Bouncy Castle for Java on the Siteminder Access Gateway r12.9 and older to Bouncy Castle 1.0.2.6
# cd <Install_Dir>/CA/secure-proxy/agentframework/java/
# mv bc-fips-1.0.2.4.jar bc-fips-1.0.2.4.jar.BAK
# cd <Install_Dir>/CA/secure-proxy/Tomcat/webapps/affwebservices/WEB-INF/lib/
# mv bc-fips-1.0.2.4.jar bc-fips-1.0.2.4.jar.BAK
# cd <Install_Dir>/CA/secure-proxy/Tomcat/thirdparty/
# mv bc-fips-1.0.2.4.jar bc-fips-1.0.2.4.jar.BAK
# cd <Install_Dir>/CA/secure-proxy/Tomcat/federation_apps/sts/webapps/WEB-INF/lib/
# mv bc-fips-1.0.2.4.jar bc-fips-1.0.2.4.jar.BAK