EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.
2014-05-16T11:11:59.383
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.6 (HIGH)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | emc | rsa_netwitness | < 9.8.5.19 | Yes |
Application | emc | rsa_security_analytics | < 10.2.4 | Yes |
Application | emc | rsa_security_analytics | < 10.3.2 | Yes |