CVE-2016-0915: High severity emc rsa authentication manager vulnerability
The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0915?
CVE-2016-0915 has been assigned a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2016-0915?
To address CVE-2016-0915, upgrade your EMC RSA Authentication Manager to version 3.1 1915.42871 or later.
What versions of EMC RSA Authentication Manager are affected by CVE-2016-0915?
CVE-2016-0915 affects EMC RSA Authentication Manager Prime versions 3.0 and 3.1 prior to 3.1 1915.42871.
What type of attack does CVE-2016-0915 enable?
CVE-2016-0915 allows remote authenticated users to escalate a denial of service by changing the PIN for any arbitrary user.
Is CVE-2016-0915 part of a larger security issue?
CVE-2016-0915 is a standalone vulnerability, but like similar issues, it highlights the need for monitoring user permissions and token validation.