SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1182

It allows certain OS level users to execute arbitrary scripts with root level privileges.

HIGH 7.8EPSS 0.41%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only). It allows certain OS level users to execute arbitrary scripts with root level privileges.

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.41% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
emc/rsa identity governance and lifecycle · emc/rsa identity management and governance · rsa/rsa via lifecycle and governance
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.