CVE-2019-3759: Code Injection
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3759?
CVE-2019-3759 has a high severity rating due to its potential for remote code execution by authenticated users.
How do I fix CVE-2019-3759?
To fix CVE-2019-3759, upgrade the RSA Identity Governance and Lifecycle software to version 7.1.0 P08 or later.
Who is affected by CVE-2019-3759?
CVE-2019-3759 affects versions of RSA Identity Governance and Lifecycle prior to 7.1.0 P08, including 7.0.1 and 7.0.2.
What type of vulnerability is CVE-2019-3759?
CVE-2019-3759 is a code injection vulnerability that allows remote authenticated users to execute custom Groovy scripts.
What are the risks of CVE-2019-3759?
Exploiting CVE-2019-3759 could lead to unauthorized access and manipulation of sensitive data by running malicious scripts.