First published: Mon Nov 25 2019(Updated: )
RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Manager | =8.4 | |
EMC RSA Authentication Manager | =8.4-p1 | |
EMC RSA Authentication Manager | =8.4-p2 | |
EMC RSA Authentication Manager | =8.4-p3 | |
EMC RSA Authentication Manager | =8.4-p4 | |
EMC RSA Authentication Manager | =8.4-p5 | |
EMC RSA Authentication Manager | =8.4-p6 | |
EMC RSA Authentication Manager | =8.4-p7 | |
RSA Authentication Manager | <8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-18574 is medium.
RSA Authentication Manager software versions prior to 8.4 P8 are affected by CVE-2019-18574.
The CWE ID associated with CVE-2019-18574 is 79.
A malicious Security Console administrator could exploit CVE-2019-18574 by storing arbitrary HTML or JavaScript code through the web interface.
Yes, you can find more information about CVE-2019-18574 at this link: https://www.dell.com/support/security/en-us/details/DOC-109297/DSA-2019-168-RSA®-Authentication-Manager-Software-Stored-Cross-Site-Scripting-Vulnerability