First published: Thu Feb 28 2019(Updated: )
RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Manager | =8.4 | |
RSA Authentication Manager | <8.4 | |
=8.4 | ||
<8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3711 is a vulnerability in RSA Authentication Manager versions prior to 8.4 P1 that allows a malicious administrator to obtain and use domain passwords.
CVE-2019-3711 has a severity rating of 7.2, which is categorized as high.
RSA Authentication Manager versions prior to 8.4 P1 are affected by CVE-2019-3711.
A malicious Operations Console administrator can obtain and use domain passwords set by another administrator.
Yes, you can find more information about CVE-2019-3711 at these references: http://www.securityfocus.com/bid/107210 and https://seclists.org/fulldisclosure/2019/Mar/5