PT-2018-11183 · Rsa · Rsa Identity Governance/Lifecycle

Lukasz Plonka

·

Publicado

2018-07-13

·

Atualizado

2019-10-09

·

CVE-2018-1245

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RSA Identity Lifecycle and Governance versions 7.0.1 through 7.1.0
Description The issue concerns an authorization bypass within the workflow architect component, allowing a remote authenticated malicious user with non-admin privileges to bypass Java Security Policies. This could enable the malicious user to run arbitrary system commands at the OS level with application owner privileges on the affected system.
Recommendations For RSA Identity Lifecycle and Governance versions 7.0.1 through 7.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1245

Produtos afetados

Rsa Identity Governance/Lifecycle