ZeroHour

CVE-2018-11049

CVSS 3.0
7.3 high
EPSS
<1%p38
Published
()
Modified
Description

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

Vendors
emcrsa
Products
rsa identity governance and lifecycle, rsa identity management and governance, rsa via lifecycle and governance
Weakness
CWE-427
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.