CVE-2018-11061
RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product. A remote authenticated malicious RSA NetWitness Server user with an Admin or Operator role could exploit this vulnerability to execute arbitrary commands on the server with root privileges.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 4.98% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- emc/rsa netwitness · emc/rsa security analytics
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2018/Aug/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105134Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041541Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041542Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Aug/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105134Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041541Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041542Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.