CVE-2019-3725: Command Injection vulnerability
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3725?
CVE-2019-3725 is a Command Injection vulnerability in RSA Netwitness Platform and RSA Security Analytics.
How severe is CVE-2019-3725?
CVE-2019-3725 has a severity rating of 9.8, which is considered critical.
Which versions of RSA Netwitness Platform are affected by CVE-2019-3725?
RSA Netwitness Platform versions prior to 11.2.1.1 are affected by CVE-2019-3725.
Which versions of RSA Security Analytics are affected by CVE-2019-3725?
RSA Security Analytics versions prior to 10.6.6.1 are affected by CVE-2019-3725.
How can the Command Injection vulnerability in RSA Netwitness Platform and RSA Security Analytics be exploited?
A remote unauthenticated malicious user can exploit this vulnerability to execute arbitrary commands.