CVE-2019-3760: Input Validation
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the data by supplying specially crafted input data to the affected application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3760?
CVE-2019-3760 has been classified as a critical SQL injection vulnerability.
How do I fix CVE-2019-3760?
To mitigate CVE-2019-3760, upgrade the RSA Identity Governance and Lifecycle software to version 7.1.0 P08 or later.
What products are affected by CVE-2019-3760?
CVE-2019-3760 affects RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products before version 7.1.0 P08.
What type of vulnerability is CVE-2019-3760?
CVE-2019-3760 is a SQL Injection vulnerability found in the Workflow Architect component.
Who could exploit CVE-2019-3760?
A remote authenticated malicious user could potentially exploit CVE-2019-3760 to execute SQL commands on the back-end database.