CVE-2018-11051: RSA Certificate Manager Path Traversal Vulnerability
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11051?
The severity of CVE-2018-11051 is high with a severity value of 7.5.
What is the vulnerability in RSA Certificate Manager Versions 6.9?
The vulnerability in RSA Certificate Manager Versions 6.9 is a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server.
How can an attacker exploit CVE-2018-11051?
A remote unauthenticated attacker can exploit CVE-2018-11051 by manipulating input parameters of the application.
Which software versions are affected by CVE-2018-11051?
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 are affected by CVE-2018-11051.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-11051?
The Common Weakness Enumeration (CWE) ID for CVE-2018-11051 is 22.