CVE-2017-8005: XSS
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple stored cross-site scripting vulnerabilities. Remote authenticated malicious users could potentially inject arbitrary HTML code to the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8005?
CVE-2017-8005 has been classified as a critical vulnerability affecting EMC RSA Identity Governance and Lifecycle products.
How do I fix CVE-2017-8005?
To fix CVE-2017-8005, you need to apply the latest security patch provided by EMC for the affected RSA Identity Governance and Lifecycle software versions.
Which versions are affected by CVE-2017-8005?
CVE-2017-8005 affects RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, as well as RSA Via Lifecycle and Governance and other specified versions.
What are the consequences of CVE-2017-8005 exploitation?
Exploitation of CVE-2017-8005 could allow an attacker to gain unauthorized access to sensitive data and potentially compromise the integrity of identity management processes.
What should I do if I am using affected software with CVE-2017-8005?
If you are using affected software, immediately implement the recommended patches from EMC to mitigate the risk associated with CVE-2017-8005.