CVE-2018-11049
11.07.2018, 20:29
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.Enginsight
Vendor | Product | Version |
---|---|---|
emc | rsa_identity_governance_and_lifecycle | 7.1.0 |
emc | rsa_identity_management_and_governance | 6.9.0 |
emc | rsa_identity_management_and_governance | 6.9.1 |
rsa | rsa_via_lifecycle_and_governance | 7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration