5.8

CVE-2020-5359

Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Bsafe Micro-edition-suite Version < 4.5
Oracle ≫ Database Version 12.1.0.2 SwEdition enterprise
Oracle ≫ Database Version 12.2.0.1 SwEdition enterprise
Oracle ≫ Database Version 18c SwEdition enterprise
Oracle ≫ Database Version 19c SwEdition enterprise
Oracle ≫ Weblogic Server Proxy Plug-in Version 11.1.1.9.0
Oracle ≫ Weblogic Server Proxy Plug-in Version 12.2.1.3.0
Oracle ≫ Weblogic Server Proxy Plug-in Version 12.2.1.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.664
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
EMC 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWE-252 Unchecked Return Value

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

CWE-544 Missing Standardized Error Handling Mechanism

The product does not use a standardized method for handling errors throughout the code, which might introduce inconsistent error handling and resultant weaknesses.

https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://www.dell.com/support/kbdoc/en-us/000181098/dsa-2020-114-dell-bsafe-micro-edition-suite-multiple-security-vulnerabilities
Vendor Advisory