CVE-2018-11056 Details
Description
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell bsafe | >= 4.1.0, < 4.1.6.1 |
CPE
Remediation
| |
| dell bsafe crypto-c | >= 4.0.0, < 4.0.5.3 |
CPE
Remediation
| |
| oracle application testing suite | 13.3.0.1 |
CPE
Remediation
| |
| oracle communications analytics | 12.1.1 |
CPE
Remediation
| |
| oracle communications ip service activator | 7.3.0 7.4.0 |
CPE
Remediation
| |
| oracle core rdbms | 11.2.0.4 12.1.0.2 12.2.0.1 18c 19c |
CPE
Remediation
| |
| oracle enterprise manager ops center | 12.3.3 12.4.0 |
CPE
Remediation
| |
| oracle goldengate application adapters | 12.3.2.1.0 |
CPE
Remediation
| |
| oracle jd edwards enterpriseone tools | 9.2 |
CPE
Remediation
| |
| oracle real user experience insight | 13.1.2.1 13.2.3.1 13.3.1.0 |
CPE
Remediation
| |
| oracle retail predictive application server | 15.0.3 16.0.3.0 |
CPE
Remediation
| |
| oracle security service | 11.1.1.9.0 12.1.3.0.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle timesten in-memory database | < 18.1.4.1.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 18, 2022 | Modified Analysis | [email protected] |
| Nov 30, 2021 | CPE Deprecation Remap | [email protected] |
| Nov 30, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Jan 22, 2020 | CPE Deprecation Remap | [email protected] |
| Jan 15, 2020 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| Nov 8, 2018 | Initial Analysis | [email protected] |