CVE-2018-1245
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security Policies. Once bypassed, a malicious user could potentially run arbitrary system commands at the OS level with application owner privileges on the affected system.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- emc/rsa identity governance and lifecycle
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2018/Jul/46Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1041287Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Jul/46Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1041287Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.