CVE-2019-3763: High severity rsa identity governance and lifecycle vulnerability
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Office 365 connector debug log file. An authenticated malicious local user with access to the debug logs may obtain the exposed password to use in further attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3763?
CVE-2019-3763 has a medium severity rating due to the potential exposure of sensitive information.
What products are affected by CVE-2019-3763?
CVE-2019-3763 affects multiple versions of the RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to version 7.1.0 P08.
How do I fix CVE-2019-3763?
To fix CVE-2019-3763, upgrade to version 7.1.0 P08 or later of the affected products.
What type of vulnerability is CVE-2019-3763?
CVE-2019-3763 is classified as an information exposure vulnerability.
What can an attacker do with CVE-2019-3763?
An authenticated attacker could exploit CVE-2019-3763 to access Office 365 user passwords logged in plain text in a debug log file.