Emc Rsa Identity Governance And Lifecycle vulnerabilities

8 known vulnerabilities affecting emc/rsa_identity_governance_and_lifecycle.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2018-1245HIGHCVSS 8.8v7.0.1v7.0.2+1 more2018-07-13
CVE-2018-1245 [HIGH] CWE-863 CVE-2018-1245: RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypa RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security Policies. Once bypassed, a malicious user could potentially run arbitrary system com
nvd
CVE-2018-1255MEDIUMCVSS 6.1v7.0.1v7.0.2+1 more2018-07-13
CVE-2018-1255 [MEDIUM] CWE-79 CVE-2018-1255: RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-sit RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to t
nvd
CVE-2018-11049HIGHCVSS 7.3v7.1.02018-07-11
CVE-2018-11049 [HIGH] CWE-427 CVE-2018-11049: RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have a RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
nvd
CVE-2018-1182HIGHCVSS 7.8v7.0.1v7.0.22018-03-08
CVE-2018-1182 [HIGH] CWE-269 CVE-2018-1182: An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patc An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.
nvd
CVE-2017-8004HIGHCVSS 7.2v7.0.1v7.0.1.1+4 more2017-07-17
CVE-2017-8004 [HIGH] CWE-20 CVE-2017-8004: The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) allow an application adminis
nvd
CVE-2017-8005MEDIUMCVSS 5.4v7.0.1v7.0.1.1+4 more2017-07-17
CVE-2017-8005 [MEDIUM] CWE-79 CVE-2017-8005: The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG product The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple
nvd
CVE-2017-5003MEDIUMCVSS 6.1v7.0.1v7.0.22017-06-09
CVE-2017-5003 [MEDIUM] CWE-79 CVE-2017-5003: EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycl EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Reflected Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an
nvd
CVE-2017-5004MEDIUMCVSS 5.4v7.0.1v7.0.22017-06-09
CVE-2017-5004 [MEDIUM] CWE-79 CVE-2017-5004: EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycl EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an af
nvd