First published: Mon Jul 06 2020(Updated: )
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Bsafe Crypto-c-micro-edition | <4.1.5 | |
Dell Bsafe Micro-edition-suite | <4.6 | |
Oracle Database | =12.1.0.2 | |
Oracle Database | =19c | |
Oracle Database | =21c | |
Oracle HTTP Server | =12.2.1.3.0 | |
Oracle HTTP Server | =12.2.1.4.0 | |
Oracle Security Service | =12.2.1.3.0 | |
Oracle Security Service | =12.2.1.4.0 | |
Oracle Weblogic Server Proxy Plug-in | =12.2.1.3.0 | |
Oracle Weblogic Server Proxy Plug-in | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35168 is a vulnerability in Dell BSAFE Crypto-C Micro Edition versions before 4.1.5 and Dell BSAFE Micro Edition Suite versions before 4.6 that allows for an Observable Timing Discrepancy.
Dell BSAFE Crypto-C Micro Edition versions before 4.1.5 and Dell BSAFE Micro Edition Suite versions before 4.6 are affected by CVE-2020-35168.
CVE-2020-35168 has a severity level of 9.8 (Critical).
To fix CVE-2020-35168, upgrade to Dell BSAFE Crypto-C Micro Edition version 4.1.5 or later or Dell BSAFE Micro Edition Suite version 4.6 or later.
You can find more information about CVE-2020-35168 on the Dell support website and the Oracle security alerts website.