← Back

CVE-2018-11055

nvd nist
Published: Aug 31, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.

Affected (24)

1 product
Bsafe
11 products
Application Testing Suite
Communications Analytics
Core Rdbms
Enterprise Manager Ops Center
Goldengate Application Adapters
Jd Edwards Enterpriseone Tools
Real User Experience Insight
Security Service
Timesten In Memory Database
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Dell
From 4.0.0 to 4.0.11
From 4.1.0 to 4.1.6.1
Configuration B
22 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.3.0.1
Version 12.1.1
Oracle
Version 7.3.0
Version 7.4.0
Oracle
Version 11.2.0.4
Version 12.1.0.2
Version 12.2.0.1
Version 18c
Version 19c
Oracle
Version 12.3.3
Version 12.4.0
Version 12.3.2.1.0
Version 9.2
Oracle
Version 13.1.2.1
Version 13.2.3.1
Version 13.3.1.0
Oracle
Version 15.0.3
Version 16.0.3.0
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Before 18.1.4.1.0

References (12)

Source: security_alert@emc.com
Mailing ListThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.