PT-2015-4696 · Emc · Rsa Identity Management/Governance
Publicado
2015-05-01
·
Atualizado
2016-04-01
·
CVE-2015-0532
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC RSA Identity Management and Governance (IMG) versions 6.9 before P04 and 6.9.1 before P01
Description
The issue allows remote attackers to obtain access via crafted use of the password reset process for an arbitrary valid account name, potentially affecting privileged accounts. This is due to improper restriction of password resets.
Recommendations
For versions 6.9 before P04, apply patch P04 to resolve the issue.
For versions 6.9.1 before P01, apply patch P01 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rsa Identity Management/Governance