CVE-2020-35167: Infoleak
Published Jul 11, 2022
·Updated
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
Affected Software
11 affected components
Dell Bsafe Crypto-c-micro-edition<4.1.5
Dell Bsafe Micro-edition-suite<4.6
Oracle Database=12.1.0.2
Oracle Database=19c
Oracle Database=21c
Oracle HTTP Server=12.2.1.3.0
Oracle HTTP Server=12.2.1.4.0
Oracle Security Service=12.2.1.3.0
Oracle Security Service=12.2.1.4.0
Oracle Weblogic Server Proxy Plug-in=12.2.1.3.0
Oracle Weblogic Server Proxy Plug-in=12.2.1.4.0
Remediation
Patch Available
Event History
Jul 11, 2022
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-35167.
2
What is the severity level of CVE-2020-35167?
The severity level of CVE-2020-35167 is critical (9.8).
3
Which software versions are affected by CVE-2020-35167?
Dell BSAFE Crypto-C Micro Edition versions before 4.1.5 and Dell BSAFE Micro Edition Suite versions before 4.6 are affected by CVE-2020-35167.
4
How can I fix CVE-2020-35167?
To fix CVE-2020-35167, update your Dell BSAFE Crypto-C Micro Edition to version 4.1.5 or later and Dell BSAFE Micro Edition Suite to version 4.6 or later.
5
Where can I find more information about CVE-2020-35167?
More information about CVE-2020-35167 can be found on the Dell support website and the Oracle security alerts page.