CVE-2019-3711: DSA-2019-038: RSA® Authentication Manager Insecure Credential Management Vulnerability
RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3711?
CVE-2019-3711 is a vulnerability in RSA Authentication Manager versions prior to 8.4 P1 that allows a malicious administrator to obtain and use domain passwords.
How severe is CVE-2019-3711?
CVE-2019-3711 has a severity rating of 7.2, which is categorized as high.
Which versions of RSA Authentication Manager are affected by CVE-2019-3711?
RSA Authentication Manager versions prior to 8.4 P1 are affected by CVE-2019-3711.
How can a malicious administrator exploit CVE-2019-3711?
A malicious Operations Console administrator can obtain and use domain passwords set by another administrator.
Are there any references available for CVE-2019-3711?
Yes, you can find more information about CVE-2019-3711 at these references: http://www.securityfocus.com/bid/107210 and https://seclists.org/fulldisclosure/2019/Mar/5