Command injection in RSA Identity Governance and Lifecycle - CVE-2018-1245
Published: July 13, 2018
RSA Identity Governance and Lifecycle
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The weakness exists due to insufficient sanitization of user-supplied data. A remote attacker can bypass Java Security Policies to inject and execute arbitrary system commands on the target system with the privileges of the target application.