PT-2018-10275 · Rsa · Rsa Security Analytics+1
Publicado
2018-08-24
·
Atualizado
2019-10-09
·
CVE-2018-11061
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RSA NetWitness Platform versions prior to 11.1.0.2
RSA Security Analytics versions prior to 10.6.6
Description
The issue is related to a server-side template injection vulnerability caused by the insecure configuration of the template engine. A remote authenticated malicious user with an Admin or Operator role could exploit this to execute arbitrary commands on the server with root privileges.
Recommendations
For RSA NetWitness Platform versions prior to 11.1.0.2, update to version 11.1.0.2 or later to resolve the issue.
For RSA Security Analytics versions prior to 10.6.6, update to version 10.6.6 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rsa Netwitness Platform
Rsa Security Analytics