CVE-2018-11049
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- emc/rsa identity governance and lifecycle · emc/rsa identity management and governance · rsa/rsa via lifecycle and governance
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2018/Jul/23Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/104722Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041228Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Jul/23Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/104722Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041228Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.