PT-2018-11183 · Rsa · Rsa Identity Governance/Lifecycle

Lukasz Plonka

·

Published

2018-07-13

·

Updated

2019-10-09

·

CVE-2018-1245

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RSA Identity Lifecycle and Governance versions 7.0.1 through 7.1.0
Description The issue concerns an authorization bypass within the workflow architect component, allowing a remote authenticated malicious user with non-admin privileges to bypass Java Security Policies. This could enable the malicious user to run arbitrary system commands at the OS level with application owner privileges on the affected system.
Recommendations For RSA Identity Lifecycle and Governance versions 7.0.1 through 7.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1245

Affected Products

Rsa Identity Governance/Lifecycle