CVE-2018-11049
RSA Identity Governance and Lifecycle Uncontrolled Search Path Vulnerability
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
11 jul 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Productos afectados
Pivotal · Pivotal Operations Manager¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →