VulnerabilityModified
CVE-2016-0918
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
MEDIUM 4.3EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- emc/rsa identity management and governance · emc/rsa via lifecycle and governance
- Source
- security_alert@emc.com
References
- http://seclists.org/bugtraq/2016/Sep/52Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/93108
- http://www.securitytracker.com/id/1036896
- http://seclists.org/bugtraq/2016/Sep/52Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/93108
- http://www.securitytracker.com/id/1036896
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.