CVE-2018-11055
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.
RSA BSAFE Micro Edition Suite, en versiones anteriores a la 4.0.11 (en las 4.0.x) y anteriores a la 4.1.6.1 (en las 4.1.x), contiene una vulnerabilidad de limpieza indebida de memoria dinámica (heap) antes de liberarla ("Heap Inspection"). Los datos PKCS #12 descifrados en la memoria dinámica no se convierten a cero por MES antes de liberar la memoria internamente. Un usuario local malicioso podría obtener acceso a los datos no autorizados mediante la inspección del heap.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-08-29 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Aug/46 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.0.0 < 4.0.11 Search vendor "Dell" for product "Bsafe" and version " >= 4.0.0 < 4.0.11" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.1.0 < 4.1.6.1 Search vendor "Dell" for product "Bsafe" and version " >= 4.1.0 < 4.1.6.1" | micro_edition_suite |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Analytics Search vendor "Oracle" for product "Communications Analytics" | 12.1.1 Search vendor "Oracle" for product "Communications Analytics" and version "12.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.3.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.4.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 11.2.0.4 Search vendor "Oracle" for product "Core Rdbms" and version "11.2.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.1.0.2 Search vendor "Oracle" for product "Core Rdbms" and version "12.1.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.2.0.1 Search vendor "Oracle" for product "Core Rdbms" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 18c Search vendor "Oracle" for product "Core Rdbms" and version "18c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 19c Search vendor "Oracle" for product "Core Rdbms" and version "19c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.4.0 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Application Adapters Search vendor "Oracle" for product "Goldengate Application Adapters" | 12.3.2.1.0 Search vendor "Oracle" for product "Goldengate Application Adapters" and version "12.3.2.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jd Edwards Enterpriseone Tools Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" | 9.2 Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.1.2.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.1.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.2.3.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.2.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.3.1.0 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0.3.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 11.1.1.9.0 Search vendor "Oracle" for product "Security Service" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.1.3.0.0 Search vendor "Oracle" for product "Security Service" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.2.1.3.0 Search vendor "Oracle" for product "Security Service" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Timesten In-memory Database Search vendor "Oracle" for product "Timesten In-memory Database" | < 18.1.4.1.0 Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 18.1.4.1.0" | - |
Affected
|