RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDell Bsafe
APPDell4.0.0 – 4.0.11 (bez)4.1.0 – 4.1.6.2 (bez)Oracle Application Testing Suite
APPOracle13.3.0.1Oracle Communications Analytics
APPOracle12.1.1Oracle Communications Ip Service Activator
APPOracle7.3.07.4.0Oracle Core Rdbms
APPOracle11.2.0.412.1.0.212.2.0.118c19cOracle Enterprise Manager Ops Center
APPOracle12.3.312.4.0Oracle Goldengate Application Adapters
APPOracle12.3.2.1.0Oracle Jd Edwards Enterpriseone Tools
APPOracle9.2Oracle Real User Experience Insight
APPOracle13.1.2.113.2.3.113.3.1.0Oracle Retail Predictive Application Server
APPOracle15.0.316.0.3.0Oracle Security Service
APPOracle11.1.1.9.012.1.3.0.012.2.1.3.0Oracle Timesten In Memory Database
APPOracle< 18.1.4.1.0
Powiązane podatności
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Krytyczna podatność w Oracle Application Testing Suite — przejęcie systemu
Krytyczna podatność w Oracle Application Testing Suite — przejęcie kontroli bez uwierzytelnienia
Krytyczna podatność w Oracle Application Testing Suite — przejęcie kontroli bez uwierzytelnienia