Path traversal in RSA Certificate Manager - CVE-2018-11051
Published: July 3, 2018 / Updated: July 3, 2018
RSA Certificate Manager
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the RSA CMP Enroll Server and the RSA REST Enroll Server due to path traversal when handling malicious input. A remote attacker can send a specially crafted request, conduct directory traversal attack and view files on the target system with the privileges of the web service.