Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11055


RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.


Published

2018-08-31T18:29:00.403

Last Modified

2024-11-21T03:42:34.767

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-404

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell bsafe < 4.0.11 Yes
Application dell bsafe < 4.1.6.1 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle communications_analytics 12.1.1 Yes
Application oracle communications_ip_service_activator 7.3.0 Yes
Application oracle communications_ip_service_activator 7.4.0 Yes
Application oracle core_rdbms 11.2.0.4 Yes
Application oracle core_rdbms 12.1.0.2 Yes
Application oracle core_rdbms 12.2.0.1 Yes
Application oracle core_rdbms 18c Yes
Application oracle core_rdbms 19c Yes
Application oracle enterprise_manager_ops_center 12.3.3 Yes
Application oracle enterprise_manager_ops_center 12.4.0 Yes
Application oracle goldengate_application_adapters 12.3.2.1.0 Yes
Application oracle jd_edwards_enterpriseone_tools 9.2 Yes
Application oracle real_user_experience_insight 13.1.2.1 Yes
Application oracle real_user_experience_insight 13.2.3.1 Yes
Application oracle real_user_experience_insight 13.3.1.0 Yes
Application oracle retail_predictive_application_server 15.0.3 Yes
Application oracle retail_predictive_application_server 16.0.3.0 Yes
Application oracle security_service 11.1.1.9.0 Yes
Application oracle security_service 12.1.3.0.0 Yes
Application oracle security_service 12.2.1.3.0 Yes
Application oracle timesten_in-memory_database < 18.1.4.1.0 Yes

References