PT-2016-4469 · Emc · Emc Rsa Authentication Manager

Published

2016-08-22

·

Updated

2020-08-27

·

CVE-2016-0915

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions EMC RSA Authentication Manager (AM) Prime Self-Service versions 3.0 through 3.1 before 3.1 1915.42871
Description The issue allows remote authenticated users to cause a denial of service, specifically a PIN change for an arbitrary user, by modifying the token serial number within a PIN change request. This is related to a direct object reference vulnerability.
Recommendations For versions 3.0 through 3.1 before 3.1 1915.42871, update to version 3.1 1915.42871 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0915

Affected Products

Emc Rsa Authentication Manager