First published: Thu Aug 28 2014(Updated: )
EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Identity Management and Governance | =6.5.0 | |
EMC RSA Identity Management and Governance | =6.5.1 | |
EMC RSA Identity Management and Governance | =6.5.2 | |
EMC RSA Identity Management and Governance | =6.8.0 | |
EMC RSA Identity Management and Governance | =6.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4619 has been classified as a high severity vulnerability due to the potential for remote attackers to bypass authentication.
To fix CVE-2014-4619, upgrade EMC RSA Identity Management and Governance software to the latest patched version including 6.5.1 P11, 6.5.2 P02HF01, or 6.8.1 P07.
CVE-2014-4619 affects EMC RSA Identity Management and Governance versions 6.5.0, 6.5.1, 6.5.2, and 6.8.0.
CVE-2014-4619 can be exploited by remote attackers to bypass authentication using an arbitrary valid username.
Yes, CVE-2014-4619 is associated with EMC RSA Identity Management and Governance software when used with Novell Identity Manager.