ZeroHour

CVE-2019-3759

CVSS 3.1
8.1 high
EPSS
3%p87
Published
()
Modified
Description

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

Vendors
dell
Products
rsa identity governance and lifecycle, rsa via lifecycle and governance
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.