Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11049


RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.


Published

2018-07-11T20:29:00.320

Last Modified

2024-11-21T03:42:33.900

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.3 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emc rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application emc rsa_identity_management_and_governance 6.9.0 Yes
Application emc rsa_identity_management_and_governance 6.9.1 Yes
Application rsa rsa_via_lifecycle_and_governance 7.0 Yes

References