CVE-2018-11049
RSA Identity Governance and Lifecycle Uncontrolled Search Path Vulnerability
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jul 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Affected products
Pivotal · Pivotal Operations ManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →