cbcvebase.

Dell Rsa Authentication Manager vulnerabilities

7 known vulnerabilities affecting dell/rsa_authentication_manager.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2019-3711P3HIGHCVSS 7.2≥ 8.4, < P12019-03-13
CVE-2019-3711 [HIGH] CVE-2019-3711: RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulner RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks.
nvd
CVE-2018-15782P3HIGHCVSS 7.8≥ unspecified, < 8.42019-01-16
CVE-2018-15782 [HIGH] CWE-22 CVE-2018-15782: The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a rel The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized
nvd
CVE-2019-3768P3MEDIUMCVSS 6.5≥ unspecified, < 8.4 P72020-01-03
CVE-2019-3768 [MEDIUM] CWE-611 CVE-2019-3768: RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.
nvd
CVE-2020-5340P4MEDIUMCVSS 4.8≥ unspecified, < AM 8.4 patch P102020-03-26
CVE-2020-5340 [MEDIUM] CWE-79 CVE-2020-5340: RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerabi RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When othe
nvd
CVE-2020-5339P4MEDIUMCVSS 4.8≥ unspecified, < AM 8.4 patch P102020-03-26
CVE-2020-5339 [MEDIUM] CWE-79 CVE-2020-5339: RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerabi RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When othe
nvd
CVE-2020-5346P4MEDIUMCVSS 4.8≥ unspecified, < AM 8.4 patch P112020-04-15
CVE-2020-5346 [MEDIUM] CWE-79 CVE-2020-5346: RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerabi RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When othe
nvd
CVE-2019-18574P4MEDIUMCVSS 4.8≥ unspecified, < 8.4 P82019-12-03
CVE-2019-18574 [MEDIUM] CWE-79 CVE-2019-18574: RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting v RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console
nvd
Dell Rsa Authentication Manager vulnerabilities | cvebase