SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-3759

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability.

HIGH 8.1EPSS 3.23%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
3.23% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
dell/rsa identity governance and lifecycle · dell/rsa via lifecycle and governance
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.