First published: Wed Jan 16 2019(Updated: )
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized access to that system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Authentication Manager | <8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15782 is a vulnerability in the Quick Setup component of RSA Authentication Manager versions prior to 8.4.
The severity of CVE-2018-15782 is high with a CVSS score of 7.8.
CVE-2018-15782 affects RSA Authentication Manager versions prior to 8.4.
A local attacker could potentially provide an administrator with a crafted license during the Quick Setup deployment of the initial RSA Authentication Manager, allowing for a relative path traversal vulnerability.
Yes, upgrading to RSA Authentication Manager version 8.4 or newer resolves the vulnerability.