First published: Fri Nov 16 2018(Updated: )
RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell BSAFE | >=4.0.0<4.0.11 | |
Dell BSAFE | >=4.1.0<4.1.6.2 | |
Oracle Application Testing Suite | =13.3.0.1 | |
oracle communications analytics | =12.1.1 | |
Oracle Communications IP Service Activator | =7.3.0 | |
Oracle Communications IP Service Activator | =7.4.0 | |
Oracle Core RDBMS | =11.2.0.4 | |
Oracle Core RDBMS | =12.1.0.2 | |
Oracle Core RDBMS | =12.2.0.1 | |
Oracle Core RDBMS | =18c | |
Oracle Core RDBMS | =19c | |
Oracle Enterprise Manager Ops Center | =12.3.3 | |
Oracle Enterprise Manager Ops Center | =12.4.0 | |
Oracle GoldenGate Application Adapters | =12.3.2.1.0 | |
Oracle JD Edwards EnterpriseOne Tools | =9.2 | |
oracle real user experience insight | =13.1.2.1 | |
oracle real user experience insight | =13.2.3.1 | |
oracle real user experience insight | =13.3.1.0 | |
Oracle Retail Predictive Application Server | =15.0.3 | |
Oracle Retail Predictive Application Server | =16.0.3.0 | |
Oracle Security Service | =11.1.1.9.0 | |
Oracle Security Service | =12.1.3.0.0 | |
Oracle Security Service | =12.2.1.3.0 | |
Oracle TimesTen In-Memory Database | <18.1.4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15769 is a vulnerability in RSA BSAFE Micro Edition Suite that could allow a malicious TLS server to cause a Denial of Service (DoS) on TLS clients during the handshake.
CVE-2018-15769 has a severity rating of 7.5, which is considered high.
CVE-2018-15769 affects RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series).
The vulnerability in CVE-2018-15769 is exploited by a malicious TLS server sending a very large prime value during the handshake, causing a DoS on TLS clients.
Yes, you can find more information about CVE-2018-15769 at the following references: [link1], [link2], [link3].