8.8

CVE-2019-18573

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update -
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p01
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p02
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p03
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p04
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p05
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p06
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p07
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.0 Update p08
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.1 Update -
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.1 Update p01
Dell ≫ Rsa Identity Governance And Lifecycle Version 7.1.1 Update p02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.578
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
EMC 8.7 2.3 5.8
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

CWE-598 Use of HTTP Request With Sensitive Query String

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.