First published: Wed Aug 22 2018(Updated: )
RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product. A remote authenticated malicious RSA NetWitness Server user with an Admin or Operator role could exploit this vulnerability to execute arbitrary commands on the server with root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA NetWitness | <11.1.0.2 | |
EMC RSA Security Analytics | <10.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11061 is critical, with a CVSS score of 9.1.
RSA NetWitness Platform versions prior to 11.1.0.2 are affected by CVE-2018-11061.
RSA Security Analytics versions prior to 10.6.6 are affected by CVE-2018-11061.
The CVE-2018-11061 vulnerability can be exploited by a remote authenticated malicious RSA NetWitness Server user.
Yes, you can find references for CVE-2018-11061 at the following links: [1] http://seclists.org/fulldisclosure/2018/Aug/32, [2] http://www.securityfocus.com/bid/105134, [3] http://www.securitytracker.com/id/1041541.