CVE-2014-0623: XSS
Cross-site scripting (XSS) vulnerability in the Self-Service Console in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0623?
CVE-2014-0623 has a medium severity rating due to its cross-site scripting (XSS) exploit potential.
How do I fix CVE-2014-0623?
To fix CVE-2014-0623, upgrade EMC RSA Authentication Manager to version 7.1 SP4 P32 or later.
What impact does CVE-2014-0623 have on my system?
CVE-2014-0623 allows remote attackers to inject arbitrary web scripts or HTML, compromising the integrity of the Self-Service Console.
Which versions of EMC RSA Authentication Manager are affected by CVE-2014-0623?
EMC RSA Authentication Manager 7.1 and versions prior to SP4 P32 are affected by CVE-2014-0623.
Is there a workaround for CVE-2014-0623?
There is no documented workaround for CVE-2014-0623; patching to the latest version is strongly recommended.