9.3
CVE-2014-4619
- EPSS 4.45%
- Veröffentlicht 28.08.2014 01:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Rsa Identity Management And Governance Version 6.5.0
Emc ≫ Rsa Identity Management And Governance Version 6.5.1
Emc ≫ Rsa Identity Management And Governance Version 6.5.2
Emc ≫ Rsa Identity Management And Governance Version 6.8.0
Emc ≫ Rsa Identity Management And Governance Version 6.8.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.45% | 0.902 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://archives.neohapsis.com/archives/bugtraq/2014-08/0133.html
http://packetstormsecurity.com/files/128005/RSA-Identity-Management-And-Governance-Authentication-Bypass.html
http://secunia.com/advisories/60281
http://www.securityfocus.com/bid/69411
http://www.securitytracker.com/id/1030759
https://exchange.xforce.ibmcloud.com/vulnerabilities/95483