CVE-2018-11057
RSA BSAFE Micro Edition Suite / Crypto-C Micro Edition Overflow / DoS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
RSA BSAFE Micro Edition Suite, en versiones anteriores a la 4.0.11 (en las 4.0.x) y anteriores a la 4.1.6.1 (en las 4.1.x) contiene una vulnerabilidad de canal de tiempo oculto durante el descifrado RSA. Esto también se conoce como ataque Bleichenbacher sobre descifrado RSA. Un atacante remoto podría ser capaz de recuperar una clave RSA.
RSA BSAFE Micro Edition Suite and Crypto-C Micro Edition suffer from resource exhaustion, integer overflow, improper clearing of heap memory, covert timing channel, and buffer over-read vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-08-29 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Aug/46 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.0.0 < 4.0.11 Search vendor "Dell" for product "Bsafe" and version " >= 4.0.0 < 4.0.11" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.1.0 < 4.1.6.1 Search vendor "Dell" for product "Bsafe" and version " >= 4.1.0 < 4.1.6.1" | micro_edition_suite |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Analytics Search vendor "Oracle" for product "Communications Analytics" | 12.1.1 Search vendor "Oracle" for product "Communications Analytics" and version "12.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.3.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.4.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 11.2.0.4 Search vendor "Oracle" for product "Core Rdbms" and version "11.2.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.1.0.2 Search vendor "Oracle" for product "Core Rdbms" and version "12.1.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.2.0.1 Search vendor "Oracle" for product "Core Rdbms" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 18c Search vendor "Oracle" for product "Core Rdbms" and version "18c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 19c Search vendor "Oracle" for product "Core Rdbms" and version "19c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.4.0 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Application Adapters Search vendor "Oracle" for product "Goldengate Application Adapters" | 12.3.2.1.0 Search vendor "Oracle" for product "Goldengate Application Adapters" and version "12.3.2.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jd Edwards Enterpriseone Tools Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" | 9.2 Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.1.2.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.1.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.2.3.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.2.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.3.1.0 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0.3.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 11.1.1.9.0 Search vendor "Oracle" for product "Security Service" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.1.3.0.0 Search vendor "Oracle" for product "Security Service" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.2.1.3.0 Search vendor "Oracle" for product "Security Service" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Timesten In-memory Database Search vendor "Oracle" for product "Timesten In-memory Database" | < 18.1.4.1.0 Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 18.1.4.1.0" | - |
Affected
|