cbcvebase.
CVE-2018-11055
published 2018-08-31

CVE-2018-11055: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release…

PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.43%
34.6th percentile
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
dellbsafe>= 4.0.0 < 4.0.114.0.11
dellbsafe>= 4.1.0 < 4.1.6.14.1.6.1
oracleapplication_testing_suite
oraclecommunications_analytics
oraclecommunications_ip_service_activator
oraclecommunications_ip_service_activator
oraclecore_rdbms
oraclecore_rdbms
oraclecore_rdbms
oraclecore_rdbms
oraclecore_rdbms
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oraclegoldengate_application_adapters
oraclejd_edwards_enterpriseone_tools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
oraclereal_user_experience_insight
oracleretail_predictive_application_server
oracleretail_predictive_application_server
oraclesecurity_service
oraclesecurity_service
oraclesecurity_service
oracletimesten_in-memory_database< 18.1.4.1.018.1.4.1.0
rsabsafe_micro_edition_suite>= unspecified < 4.0.114.0.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.