First published: Thu Mar 06 2014(Updated: )
EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Data Loss Prevention | =9.0 | |
EMC RSA Data Loss Prevention | =9.5 | |
EMC RSA Data Loss Prevention | =9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0624 has a high severity rating due to its potential to allow unauthorized privilege escalation.
To fix CVE-2014-0624, upgrade the EMC RSA Data Loss Prevention software to version 9.6-SP2 or later.
EMC RSA Data Loss Prevention versions 9.0, 9.5, and 9.6 before 9.6-SP2 are affected by CVE-2014-0624.
Yes, remote authenticated users can exploit CVE-2014-0624 to gain privileges and bypass content-reading restrictions.
The main issue with CVE-2014-0624 is improper session management, which compromises user privilege integrity.