RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
2018-07-11T20:29:00.320
2024-11-21T03:42:33.900
Modified
CVSSv3.0: 7.3 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | emc | rsa_identity_governance_and_lifecycle | 7.1.0 | Yes |
Application | emc | rsa_identity_management_and_governance | 6.9.0 | Yes |
Application | emc | rsa_identity_management_and_governance | 6.9.1 | Yes |
Application | rsa | rsa_via_lifecycle_and_governance | 7.0 | Yes |