PT-2018-10270 · Rsa · Emc Rsa Certificate Manager+2

Publicado

2018-07-03

·

Atualizado

2019-10-09

·

CVE-2018-11051

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564
Description The issue allows a remote unauthenticated attacker to potentially gain unauthorized read access to files stored on the server filesystem by manipulating input parameters of the application. This is due to a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server.
Recommendations For RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564, consider restricting access to the RSA CMP Enroll Server and the RSA REST Enroll Server until a patch is available. As a temporary workaround, limit the privileges of the running web application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11051

Produtos afetados

Rsa Cmp Enroll Server
Emc Rsa Certificate Manager
Rsa Rest Enroll Server