PT-2018-10270 · Rsa · Emc Rsa Certificate Manager+2

Published

2018-07-03

·

Updated

2019-10-09

·

CVE-2018-11051

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564
Description The issue allows a remote unauthenticated attacker to potentially gain unauthorized read access to files stored on the server filesystem by manipulating input parameters of the application. This is due to a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server.
Recommendations For RSA Certificate Manager versions 6.9 build 560 through 6.9 build 564, consider restricting access to the RSA CMP Enroll Server and the RSA REST Enroll Server until a patch is available. As a temporary workaround, limit the privileges of the running web application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11051

Affected Products

Rsa Cmp Enroll Server
Emc Rsa Certificate Manager
Rsa Rest Enroll Server