Executive brief
Dell BSAFE SSL-J is a Java-based security library used to provide encrypted communications for applications. A vulnerability in how the library manages system resources allows an unauthenticated attacker to overwhelm the system, causing it to crash or become unresponsive. This can lead to a total service outage for any application relying on this library for secure connections.
Technical details
Dell BSAFE SSL-J versions prior to 7.4 are vulnerable to a resource exhaustion flaw (CWE-770). The library fails to properly limit or throttle the allocation of resources during certain operations, such as SSL session caching. An unauthenticated remote attacker can exploit this over a network by sending crafted requests that consume excessive system memory or processing power, resulting in a Denial of Service (DoS) condition. The vulnerability is addressed in version 7.4. A temporary mitigation involves manually setting the 'javax.net.ssl.sessionCacheSize' property to a specific limit.
Affected products
- Dell BSAFE SSL-J Versions prior to 7.4
Timeline
- 2025-12-02: disclosed: Initial release of Dell Security Advisory DSA-2025-432
- 2026-06-02: patched: Public CVE details and remediation version 7.4 confirmed
- 2026-06-04: advisory: NVD publication date