PT-2013-5964 · Emc+1 · Rsa Security Analytics+1
Publicado
2013-12-09
·
Atualizado
2014-01-08
·
CVE-2013-6180
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC RSA Security Analytics (SA) versions prior to 10.3
RSA NetWitness NextGen version 9.8
Description
The issue allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent, as the software does not ensure that SA Core requests originate from the SA REST UI.
Recommendations
For EMC RSA Security Analytics (SA) versions prior to 10.3, update to version 10.3 or later to resolve the issue.
For RSA NetWitness NextGen version 9.8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rsa Security Analytics
Rsa Netwitness Nextgen