Emc Rsa Identity Management And Governance vulnerabilities

11 known vulnerabilities affecting emc/rsa_identity_management_and_governance.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2018-11049HIGHCVSS 7.3v6.9.0v6.9.12018-07-11
CVE-2018-11049 [HIGH] CWE-427 CVE-2018-11049: RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have a RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
nvd
CVE-2018-1182HIGHCVSS 7.8v6.9.0v6.9.12018-03-08
CVE-2018-1182 [HIGH] CWE-269 CVE-2018-1182: An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patc An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.
nvd
CVE-2017-8004HIGHCVSS 7.2v6.9.1v6.9.1.1+23 more2017-07-17
CVE-2017-8004 [HIGH] CWE-20 CVE-2017-8004: The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) allow an application adminis
nvd
CVE-2017-8005MEDIUMCVSS 5.4v6.9.1v6.9.1.1+23 more2017-07-17
CVE-2017-8005 [MEDIUM] CWE-79 CVE-2017-8005: The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG product The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple
nvd
CVE-2017-5003MEDIUMCVSS 6.1v6.9.12017-06-09
CVE-2017-5003 [MEDIUM] CWE-79 CVE-2017-5003: EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycl EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Reflected Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an
nvd
CVE-2017-5004MEDIUMCVSS 5.4v6.9.12017-06-09
CVE-2017-5004 [MEDIUM] CWE-79 CVE-2017-5004: EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycl EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an af
nvd
CVE-2016-0918MEDIUMCVSS 4.3≤ 6.8.1v6.9.0+1 more2016-09-24
CVE-2016-0918 [MEDIUM] CWE-200 CVE-2016-0918: EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via L EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
nvd
CVE-2015-4539MEDIUMCVSS 4.3≤ 6.9.12015-09-26
CVE-2015-4539 [MEDIUM] CWE-79 CVE-2015-4539: Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 7.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-4540LOWCVSS 3.5≥ 6.8.0, ≤ 6.8.1≥ 6.9.0, ≤ 6.9.12015-09-26
CVE-2015-4540 [LOW] CWE-79 CVE-2015-4540: Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x before 6.9.1 P6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-0532HIGHCVSS 7.5v6.9.0v6.9.12015-05-01
CVE-2015-0532 [HIGH] CWE-264 CVE-2015-0532: EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not proper EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.
nvd
CVE-2014-4619CRITICALCVSS 9.3v6.5.0v6.5.1+3 more2014-08-28
CVE-2014-4619 [CRITICAL] CWE-287 CVE-2014-4619: EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6 EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username.
nvd