First published: Wed Jul 11 2018(Updated: )
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Identity Governance and Lifecycle | =7.1.0 | |
EMC RSA Identity Management and Governance | =6.9.0 | |
EMC RSA Identity Management and Governance | =6.9.1 | |
Rsa Rsa Via Lifecycle And Governance | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11049 is a vulnerability in RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases that allows a local authenticated malicious user to run malicious code as root.
CVE-2018-11049 has a severity rating of 7.3 out of 10, which is considered high.
Exploiting CVE-2018-11049 requires local authentication and the ability to trick the root user into running malicious code.
Yes, to fix CVE-2018-11049, it is recommended to apply the appropriate patches and updates provided by RSA.
You can find more information about CVE-2018-11049 on the following references: [1] http://seclists.org/fulldisclosure/2018/Jul/23 [2] http://www.securityfocus.com/bid/104722 [3] http://www.securitytracker.com/id/1041228