CVE-2018-11056: Dell Bsafe

Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.

RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.

Affected products

  • Dell Bsafe: from 4.1.0, before 4.1.6.1 (fixed in 4.1.6.1)
  • Dell Bsafe Crypto-C: from 4.0.0, before 4.0.5.3 (fixed in 4.0.5.3)
  • Oracle Application Testing Suite: version 13.3.0.1 only
  • Oracle Communications Analytics: version 12.1.1 only
  • Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
  • Oracle Core Rdbms: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle Goldengate Application Adapters: version 12.3.2.1.0 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Real User Experience Insight: version 13.1.2.1 only; version 13.2.3.1 only; version 13.3.1.0 only
  • Oracle Retail Predictive Application Server: version 15.0.3 only; version 16.0.3.0 only
  • Oracle Security Service: version 11.1.1.9.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Timesten In-Memory Database: before 18.1.4.1.0 (fixed in 18.1.4.1.0)

Published 2018-08-31. Last modified 2026-06-17.