Medium severity5.5NVD Advisory· Published Aug 31, 2018· Updated Jun 17, 2026
CVE-2018-11055
CVE-2018-11055
Description
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.
Affected products
2- Range: <4.0.11 (4.0.x), <4.1.6.1 (4.1.x)
- RSA/BSAFE Micro Edition Suitev5Range: unspecified
Patches
Vulnerability mechanics
References
6- www.oracle.com/security-alerts/cpuapr2020.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujan2020.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujul2020.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdPatchThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdPatchThird Party Advisory
- seclists.org/fulldisclosure/2018/Aug/46nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.