CVE-2018-11049 Information
Feb 14, 2021
cve
Description
RSA Identity Governance and Lifecycle RSA Via Lifecycle and Governance and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Reference
http://seclists.org/fulldisclosure/2018/Jul/23 http://www.securityfocus.com/bid/104722 http://www.securitytracker.com/id/1041228
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.3
Share on: