Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-18571


The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.


Published

2019-12-18T21:15:12.833

Last Modified

2024-11-21T04:33:19.187

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell rsa_identity_governance_and_lifecycle 7.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.1 Yes

References