Vulnerability Intelligence Report
CVE-2018-15769
RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:2.65%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| dell | bsafe | all |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | communications_analytics | 12.1.1 |
| oracle | communications_ip_service_activator | 7.3.0, 7.4.0 |
| oracle | core_rdbms | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c |
| oracle | enterprise_manager_ops_center | 12.3.3, 12.4.0 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | real_user_experience_insight | 13.1.2.1, 13.2.3.1, 13.3.1.0 |
| oracle | retail_predictive_application_server | 15.0.3, 16.0.3.0 |
| oracle | security_service | 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 |
| oracle | timesten_in-memory_database | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.650%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dell · Vendor · USA |
| Reserved | 2018-08-23T00:00:00 |
| Published | 2018-11-16T21:00:00 |
| Patch Date | 2018-11-12 |
| Last Updated | 2024-08-05T10:01:54 |
Community Chatter & Buzz