CVE-2014-0624: Low severity EMC RSA Data Loss Prevention vulnerability
EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EMC RSA Data Loss Prevention (DLP)to a version that resolves this vulnerability.Fixed in 9.6-SP2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0624?
CVE-2014-0624 has a high severity rating due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2014-0624?
To fix CVE-2014-0624, upgrade the EMC RSA Data Loss Prevention software to version 9.6-SP2 or later.
What versions of EMC RSA Data Loss Prevention are affected by CVE-2014-0624?
EMC RSA Data Loss Prevention versions 9.0, 9.5, and 9.6 before 9.6-SP2 are affected by CVE-2014-0624.
Can remote authenticated users exploit CVE-2014-0624?
Yes, remote authenticated users can exploit CVE-2014-0624 to gain privileges and bypass content-reading restrictions.
What is the main issue with CVE-2014-0624?
The main issue with CVE-2014-0624 is improper session management, which compromises user privilege integrity.