PT-2013-5964 · Emc+1 · Rsa Security Analytics+1
Published
2013-12-09
·
Updated
2014-01-08
·
CVE-2013-6180
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC RSA Security Analytics (SA) versions prior to 10.3
RSA NetWitness NextGen version 9.8
Description
The issue allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent, as the software does not ensure that SA Core requests originate from the SA REST UI.
Recommendations
For EMC RSA Security Analytics (SA) versions prior to 10.3, update to version 10.3 or later to resolve the issue.
For RSA NetWitness NextGen version 9.8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsa Security Analytics
Rsa Netwitness Nextgen