peter bassill · operator
$ cve CVE-2018-11058 JSON

CVE-2018-11058

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.01% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2018-09-14
Last modified2026-06-17

Affected (13)

VendorProduct
dellbsafe
dellbsafe crypto-c
oracleapplication testing suite
oraclecommunications analytics
oraclecommunications ip service activator
oraclecore rdbms
oracleenterprise manager ops center
oraclegoldengate application adapters
oraclejd edwards enterpriseone tools
oraclereal user experience insight
oracleretail predictive application server
oraclesecurity service
oracletimesten in-memory database

References

→ the Explorer  ·  watch your stack  ·  NVD