CVE-2017-8005

The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple stored cross-site scripting vulnerabilities. Remote authenticated malicious users could potentially inject arbitrary HTML code to the application.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
emcrsa_identity_governance_and_lifecycle
7.0.1
emcrsa_identity_governance_and_lifecycle
7.0.1.1
emcrsa_identity_governance_and_lifecycle
7.0.1.2
emcrsa_identity_governance_and_lifecycle
7.0.1.3
emcrsa_identity_governance_and_lifecycle
7.0.2
emcrsa_identity_governance_and_lifecycle
7.0.2.1
emcrsa_identity_management_and_governance
6.9.1
emcrsa_identity_management_and_governance
6.9.1.1
emcrsa_identity_management_and_governance
6.9.1.2
emcrsa_identity_management_and_governance
6.9.1.3
emcrsa_identity_management_and_governance
6.9.1.4
emcrsa_identity_management_and_governance
6.9.1.5
emcrsa_identity_management_and_governance
6.9.1.6
emcrsa_identity_management_and_governance
6.9.1.7
emcrsa_identity_management_and_governance
6.9.1.8
emcrsa_identity_management_and_governance
6.9.1.9
emcrsa_identity_management_and_governance
6.9.1.10
emcrsa_identity_management_and_governance
6.9.1.11
emcrsa_identity_management_and_governance
6.9.1.12
emcrsa_identity_management_and_governance
6.9.1.13
emcrsa_identity_management_and_governance
6.9.1.14
emcrsa_identity_management_and_governance
6.9.1.15
emcrsa_identity_management_and_governance
6.9.1.16
emcrsa_identity_management_and_governance
6.9.1.17
emcrsa_identity_management_and_governance
6.9.1.18
emcrsa_identity_management_and_governance
6.9.1.19
emcrsa_identity_management_and_governance
6.9.1.20
emcrsa_identity_management_and_governance
6.9.1.21
emcrsa_identity_management_and_governance
6.9.1.22
emcrsa_identity_management_and_governance
6.9.1.23
emcrsa_identity_management_and_governance
6.9.1.24
rsarsa_via_lifecycle_and_governance
7.0
rsarsa_via_lifecycle_and_governance
7.0.0.1
rsarsa_via_lifecycle_and_governance
7.0.0.2
rsarsa_via_lifecycle_and_governance
7.0.0.3
rsarsa_via_lifecycle_and_governance
7.0.0.4
rsarsa_via_lifecycle_and_governance
7.0.0.5
𝑥
= Vulnerable software versions