CVE-2018-11058
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.
RSA BSAFE Micro Edition Suite, en versiones anteriores a la 4.0.11 (en las 4.0.x) y anteriores a la 4.1.6 (en las 4.1.0); y RSA BSAFE Crypto-C Micro Edition, en versiones anteriores a la 4.0.5.3 (en las 4.0.x), contienen una vulnerabilidad de sobrelectura de búfer al analizar datos ASN.1. Un atacante remoto podría emplear datos ASN.1 construidos de forma maliciosa para provocar este problema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-08-29 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Aug/46 | Mailing List | |
http://www.securityfocus.com/bid/108106 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.0.0 < 4.0.11 Search vendor "Dell" for product "Bsafe" and version " >= 4.0.0 < 4.0.11" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.1.0 < 4.1.6 Search vendor "Dell" for product "Bsafe" and version " >= 4.1.0 < 4.1.6" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Crypto-c Search vendor "Dell" for product "Bsafe Crypto-c" | >= 4.0.0 < 4.0.5.3 Search vendor "Dell" for product "Bsafe Crypto-c" and version " >= 4.0.0 < 4.0.5.3" | micro |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Analytics Search vendor "Oracle" for product "Communications Analytics" | 12.1.1 Search vendor "Oracle" for product "Communications Analytics" and version "12.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.3.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Ip Service Activator Search vendor "Oracle" for product "Communications Ip Service Activator" | 7.4.0 Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 11.2.0.4 Search vendor "Oracle" for product "Core Rdbms" and version "11.2.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.1.0.2 Search vendor "Oracle" for product "Core Rdbms" and version "12.1.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 12.2.0.1 Search vendor "Oracle" for product "Core Rdbms" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 18c Search vendor "Oracle" for product "Core Rdbms" and version "18c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Core Rdbms Search vendor "Oracle" for product "Core Rdbms" | 19c Search vendor "Oracle" for product "Core Rdbms" and version "19c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.4.0 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Application Adapters Search vendor "Oracle" for product "Goldengate Application Adapters" | 12.3.2.1.0 Search vendor "Oracle" for product "Goldengate Application Adapters" and version "12.3.2.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jd Edwards Enterpriseone Tools Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" | 9.2 Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.1.2.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.1.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.2.3.1 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.2.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real User Experience Insight Search vendor "Oracle" for product "Real User Experience Insight" | 13.3.1.0 Search vendor "Oracle" for product "Real User Experience Insight" and version "13.3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0.3.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 11.1.1.9.0 Search vendor "Oracle" for product "Security Service" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.1.3.0.0 Search vendor "Oracle" for product "Security Service" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Security Service Search vendor "Oracle" for product "Security Service" | 12.2.1.3.0 Search vendor "Oracle" for product "Security Service" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Timesten In-memory Database Search vendor "Oracle" for product "Timesten In-memory Database" | < 18.1.4.1.0 Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 18.1.4.1.0" | - |
Affected
|