CVE-2019-18572
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.99% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-522
- Affected
- dell/rsa identity governance and lifecycle
- Source
- security_alert@emc.com
References
- https://community.rsa.com/docs/DOC-109310Vendor Advisory
- https://community.rsa.com/docs/DOC-109310Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.