ZeroHour

CVE-2019-3768

CVSS 3.1
6.5 medium
EPSS
1%p62
Published
()
Modified
Description

RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.

Vendors
emc
Products
rsa authentication manager
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.