CVE-2018-11049

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
References
Link Resource
http://seclists.org/fulldisclosure/2018/Jul/23 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/104722 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041228 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emc:rsa_identity_governance_and_lifecycle:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_identity_management_and_governance:6.9.0:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_identity_management_and_governance:6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:rsa:rsa_via_lifecycle_and_governance:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-11 20:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-11049

Mitre link : CVE-2018-11049

CVE.ORG link : CVE-2018-11049


JSON object : View

Products Affected

rsa

  • rsa_via_lifecycle_and_governance

emc

  • rsa_identity_management_and_governance
  • rsa_identity_governance_and_lifecycle
CWE
CWE-427

Uncontrolled Search Path Element