PT-2015-4696 · Emc · Rsa Identity Management/Governance
Published
2015-05-01
·
Updated
2016-04-01
·
CVE-2015-0532
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC RSA Identity Management and Governance (IMG) versions 6.9 before P04 and 6.9.1 before P01
Description
The issue allows remote attackers to obtain access via crafted use of the password reset process for an arbitrary valid account name, potentially affecting privileged accounts. This is due to improper restriction of password resets.
Recommendations
For versions 6.9 before P04, apply patch P04 to resolve the issue.
For versions 6.9.1 before P01, apply patch P01 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsa Identity Management/Governance