CVE-2018-11055: Dell Bsafe

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.

Affected products

  • Dell Bsafe: from 4.0.0, before 4.0.11 (fixed in 4.0.11); from 4.1.0, before 4.1.6.1 (fixed in 4.1.6.1)
  • Oracle Application Testing Suite: version 13.3.0.1 only
  • Oracle Communications Analytics: version 12.1.1 only
  • Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
  • Oracle Core Rdbms: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle Goldengate Application Adapters: version 12.3.2.1.0 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Real User Experience Insight: version 13.1.2.1 only; version 13.2.3.1 only; version 13.3.1.0 only
  • Oracle Retail Predictive Application Server: version 15.0.3 only; version 16.0.3.0 only
  • Oracle Security Service: version 11.1.1.9.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Timesten In-Memory Database: before 18.1.4.1.0 (fixed in 18.1.4.1.0)

Published 2018-08-31. Last modified 2026-06-17.