Description
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.
Published: 2018-08-31
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-3099 RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.
History

No history.

Subscriptions

Dell Bsafe
Oracle Application Testing Suite Communications Analytics Communications Ip Service Activator Core Rdbms Enterprise Manager Ops Center Goldengate Application Adapters Jd Edwards Enterpriseone Tools Real User Experience Insight Retail Predictive Application Server Security Service Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-05T07:54:36.580Z

Reserved: 2018-05-14T00:00:00.000Z

Link: CVE-2018-11055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-31T18:29:00.403

Modified: 2024-11-21T03:42:34.767

Link: CVE-2018-11055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses