First published: Fri Jul 13 2018(Updated: )
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Identity Governance and Lifecycle | =7.0.1 | |
EMC RSA Identity Governance and Lifecycle | =7.0.2 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1255 is medium with a severity value of 6.1.
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2, and 7.1.0 are affected by CVE-2018-1255.
A remote unauthenticated attacker could potentially exploit CVE-2018-1255 by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable application.
To fix CVE-2018-1255, update RSA Identity Lifecycle and Governance to a version that is not affected by the vulnerability.
You can find more information about CVE-2018-1255 at the following references: [http://seclists.org/fulldisclosure/2018/Jul/46](http://seclists.org/fulldisclosure/2018/Jul/46) and [http://www.securitytracker.com/id/1041287](http://www.securitytracker.com/id/1041287).