First published: Wed May 15 2019(Updated: )
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Netwitness | <11.2.1.1 | |
RSA Security Analytics | <10.6.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3725 is a Command Injection vulnerability in RSA Netwitness Platform and RSA Security Analytics.
CVE-2019-3725 has a severity rating of 9.8, which is considered critical.
RSA Netwitness Platform versions prior to 11.2.1.1 are affected by CVE-2019-3725.
RSA Security Analytics versions prior to 10.6.6.1 are affected by CVE-2019-3725.
A remote unauthenticated malicious user can exploit this vulnerability to execute arbitrary commands.