First published: Wed Dec 18 2019(Updated: )
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Identity Governance and Lifecycle | =7.0 | |
EMC RSA Identity Governance and Lifecycle | =7.0.1 | |
EMC RSA Identity Governance and Lifecycle | =7.0.2 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p01 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p02 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p03 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p04 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p05 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p06 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p07 | |
EMC RSA Identity Governance and Lifecycle | =7.1.0-p08 | |
EMC RSA Identity Governance and Lifecycle | =7.1.1 | |
EMC RSA Identity Governance and Lifecycle | =7.1.1-p01 | |
EMC RSA Identity Governance and Lifecycle | =7.1.1-p02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18572 has a high severity due to improper authentication vulnerabilities in the affected RSA products.
To fix CVE-2019-18572, upgrade to RSA Identity Governance and Lifecycle version 7.1.1 P03 or later.
CVE-2019-18572 affects RSA Identity Governance and Lifecycle versions prior to 7.1.1 P03.
An unauthenticated remote attacker can exploit CVE-2019-18572 by connecting to a Java JMX agent configured with plain text password authentication.
Yes, CVE-2019-18572 is related to configuration issues, specifically regarding the use of plain text authentication for JMX agents.