7.3
CVSSv3

CVE-2018-11049

Published: 11/07/2018 Updated: 06/08/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

emc rsa identity management and governance 6.9.0

emc rsa identity management and governance 6.9.1

emc rsa identity governance and lifecycle 7.1.0

rsa rsa via lifecycle and governance 7.0

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 DSA-2018-117 RSA Identity Governance and Lifecycle Uncontrolled Search Path Vulnerability Dell EMC Identifier: DSA-2018-117 CVE Identifier: CVE-2018-11049 Severity: High Severity Rating: 73 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) Affected Products: RSA(r) Identity Governance and Lifecycle v ...