Components affected by CVE-2020-35169
Hello.
We are having trouble determining whether we need to patch our Oracle database servers based on the information published in the latest CPU advisory.
We have found information on CVE-2020-35169 that appears to be conflicting in the July 2022 CPU advisory, available at https://www.oracle.com/security-alerts/cpujul2022.html, and are seeking a clarification. The Oracle Database Server Risk Matrix states that the affected component is Oracle Data - Enterprise Edition. However, other source of CVE information, such as https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35169, state that the affected component is Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2. The July CPU advisory lists Dell BSAFE Micro Edition Suite associated with this CVE in the section for Oracle Fusion Middleware Risk Matrix.