CVE-2018-11058
Severity
9.8CRITICAL
EPSS
1.6%
top 18.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 13
Description
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages15 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4Oracle▶
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plugin (RSA BSAFE Crypto-C) — CVE-2018-11058↗2020-10-15
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Platform (RSA BSAFE) — CVE-2018-11058↗2020-07-15
Oracle▶
Oracle Oracle Enterprise Manager Risk Matrix: Processing (Oracle Instant Client) — CVE-2018-11058↗2020-04-15
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Database Client (NZ) — CVE-2018-11058↗2020-01-15