Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3763


The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Office 365 connector debug log file. An authenticated malicious local user with access to the debug logs may obtain the exposed password to use in further attacks.


Published

2019-09-11T20:15:11.630

Last Modified

2024-11-21T04:42:29.020

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-532
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.0.2 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.0 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.1 Yes
Application dell rsa_identity_governance_and_lifecycle 7.1.1 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes
Application dell rsa_via_lifecycle_and_governance 7.0.0 Yes

References