585
VMScore

CVE-2018-1247

Published: 08/05/2018 Updated: 13/06/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

RSA Authentication Manager Security Console, version 8.3 and previous versions, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

Vulnerable Product Search on Vulmon Subscribe to Product

rsa authentication manager

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20180516-0 > ======================================================================= title: XXE & XSS vulnerabilities product: RSA Authentication Manager vulnerable version: 82140-build1394922, < 83 P1 fixed version: 83 P1 and later CVE nu ...
RS Authentication Manager versions prior to 83 P1 suffer from cross site scripting and XML external entity injection vulnerabilities ...