First published: Fri Aug 31 2018(Updated: )
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell BSAFE | >=4.0.0<4.0.11 | |
Dell BSAFE | >=4.1.0<4.1.6.1 | |
Oracle Application Testing Suite | =13.3.0.1 | |
oracle communications analytics | =12.1.1 | |
Oracle Communications IP Service Activator | =7.3.0 | |
Oracle Communications IP Service Activator | =7.4.0 | |
Oracle Core RDBMS | =11.2.0.4 | |
Oracle Core RDBMS | =12.1.0.2 | |
Oracle Core RDBMS | =12.2.0.1 | |
Oracle Core RDBMS | =18c | |
Oracle Core RDBMS | =19c | |
Oracle Enterprise Manager Ops Center | =12.3.3 | |
Oracle Enterprise Manager Ops Center | =12.4.0 | |
Oracle GoldenGate Application Adapters | =12.3.2.1.0 | |
Oracle JD Edwards EnterpriseOne Tools | =9.2 | |
oracle real user experience insight | =13.1.2.1 | |
oracle real user experience insight | =13.2.3.1 | |
oracle real user experience insight | =13.3.1.0 | |
Oracle Retail Predictive Application Server | =15.0.3 | |
Oracle Retail Predictive Application Server | =16.0.3.0 | |
Oracle Security Service | =11.1.1.9.0 | |
Oracle Security Service | =12.1.3.0.0 | |
Oracle Security Service | =12.2.1.3.0 | |
Oracle TimesTen In-Memory Database | <18.1.4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this RSA BSAFE Micro Edition Suite vulnerability is CVE-2018-11057.
CVE-2018-11057 is a Covert Timing Channel vulnerability, also known as a Bleichenbacher attack on RSA decryption, in RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x).
CVE-2018-11057 affects RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x).
The severity of the CVE-2018-11057 vulnerability is medium with a CVSS score of 5.9.
To fix the CVE-2018-11057 vulnerability in RSA BSAFE Micro Edition Suite, update to version 4.0.11 (for 4.0.x) or version 4.1.6.1 (for 4.1.x) or later.