First published: Mon Aug 22 2016(Updated: )
The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference vulnerability."
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Manager | =3.0 | |
EMC RSA Authentication Manager | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0915 has been assigned a medium severity rating due to its potential to cause a denial of service.
To address CVE-2016-0915, upgrade your EMC RSA Authentication Manager to version 3.1 1915.42871 or later.
CVE-2016-0915 affects EMC RSA Authentication Manager Prime versions 3.0 and 3.1 prior to 3.1 1915.42871.
CVE-2016-0915 allows remote authenticated users to escalate a denial of service by changing the PIN for any arbitrary user.
CVE-2016-0915 is a standalone vulnerability, but like similar issues, it highlights the need for monitoring user permissions and token validation.