PT-2018-10270 · Rsa · Emc Rsa Certificate Manager+2
Published
2018-07-03
·
Updated
2019-10-09
·
CVE-2018-11051
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564
Description
The issue allows a remote unauthenticated attacker to potentially gain unauthorized read access to files stored on the server filesystem by manipulating input parameters of the application. This is due to a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server.
Recommendations
For RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564, consider restricting access to the RSA CMP Enroll Server and the RSA REST Enroll Server until a patch is available. As a temporary workaround, limit the privileges of the running web application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsa Cmp Enroll Server
Emc Rsa Certificate Manager
Rsa Rest Enroll Server