Lucene search

K
cveDellCVE-2018-11049
HistoryJul 11, 2018 - 8:29 p.m.

CVE-2018-11049

2018-07-1120:29:00
CWE-427
dell
web.nvd.nist.gov
26
cve-2018-11049
rsa
identity governance
lifecycle
via lifecycle
governance
img
uncontrolled search
vulnerability
installation scripts
environment variable
local authenticated
malicious user
root user
malicious code
targeted system.

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

5.1%

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

Affected configurations

Nvd
Vulners
Node
emcrsa_identity_governance_and_lifecycleMatch7.1.0
OR
emcrsa_identity_management_and_governanceMatch6.9.0
OR
emcrsa_identity_management_and_governanceMatch6.9.1
OR
rsarsa_via_lifecycle_and_governanceMatch7.0
VendorProductVersionCPE
emcrsa_identity_governance_and_lifecycle7.1.0cpe:2.3:a:emc:rsa_identity_governance_and_lifecycle:7.1.0:*:*:*:*:*:*:*
emcrsa_identity_management_and_governance6.9.0cpe:2.3:a:emc:rsa_identity_management_and_governance:6.9.0:*:*:*:*:*:*:*
emcrsa_identity_management_and_governance6.9.1cpe:2.3:a:emc:rsa_identity_management_and_governance:6.9.1:*:*:*:*:*:*:*
rsarsa_via_lifecycle_and_governance7.0cpe:2.3:a:rsa:rsa_via_lifecycle_and_governance:7.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Pivotal Operations Manager",
    "vendor": "Pivotal",
    "versions": [
      {
        "status": "affected",
        "version": "RSA(r) Identity Governance and Lifecycle version 7.1.0, all patch levels (Hardware Appliance, Software Bundle, and  Virtual Application deployments only)"
      },
      {
        "status": "affected",
        "version": "RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels  (Hardware Appliance and Software Bundle (also known as Soft-Appliance) deployments only)."
      },
      {
        "status": "affected",
        "version": "RSA Via Lifecycle and Governance version 7.0, all patch levels (Hardware Appliance and Software Bundle (also known as  Soft-Appliance) deployments only)"
      },
      {
        "status": "affected",
        "version": "RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (Hardware Appliance and Software  Bundle (also known as Soft-Appliance)  deployments only)"
      }
    ]
  }
]

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2018-11049