CVE-2018-1245: Authorization ByPass Vulnerability
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security Policies. Once bypassed, a malicious user could potentially run arbitrary system commands at the OS level with application owner privileges on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of RSA Identity Lifecycle and Governance?
The vulnerability ID of RSA Identity Lifecycle and Governance is CVE-2018-1245.
What is the severity of CVE-2018-1245?
The severity of CVE-2018-1245 is critical with a score of 8.8.
Which software versions are affected by CVE-2018-1245?
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2, and 7.1.0 are affected by CVE-2018-1245.
What is the risk of CVE-2018-1245?
The risk of CVE-2018-1245 is an authorization bypass vulnerability that allows a remote authenticated malicious user to bypass Java Security Policies.
Are there any references for CVE-2018-1245?
Yes, you can find references for CVE-2018-1245 at these links: [http://seclists.org/fulldisclosure/2018/Jul/46](http://seclists.org/fulldisclosure/2018/Jul/46) and [http://www.securitytracker.com/id/1041287](http://www.securitytracker.com/id/1041287).