CVE-2017-15546

The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
emcrsa_authentication_manager
𝑥
≤ 8.2
emcrsa_authentication_manager
8.2:sp1
emcrsa_authentication_manager
8.2:sp1_p1
emcrsa_authentication_manager
8.2:sp1_p2
emcrsa_authentication_manager
8.2:sp1_p3
emcrsa_authentication_manager
8.2:sp1_p4
emcrsa_authentication_manager
8.2:sp1_p5
emcrsa_authentication_manager
8.2:sp1_p6
𝑥
= Vulnerable software versions