SB2015050101 - Multiple vulnerabilities in RSA Identity Management and Governance



SB2015050101 - Multiple vulnerabilities in RSA Identity Management and Governance

Published: May 1, 2015 Updated: August 9, 2020

Security Bulletin ID SB2015050101
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2016-0918)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-0532)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.


Remediation

Install update from vendor's website.