9.8

CVE-2020-35167

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

Data is provided by the National Vulnerability Database (NVD)
DellBsafe Crypto-c-micro-edition Version < 4.1.5
DellBsafe Micro-edition-suite Version < 4.6
OracleDatabase Version12.1.0.2 SwEditionenterprise
OracleDatabase Version19c SwEditionenterprise
OracleDatabase Version21c SwEditionenterprise
OracleHTTP Server Version12.2.1.3.0
OracleHTTP Server Version12.2.1.4.0
OracleSecurity Service Version12.2.1.3.0
OracleSecurity Service Version12.2.1.4.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.3.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.65% 0.698
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security_alert@emc.com 4.8 0.4 4
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.