Privilege escalation in RSA Security Analytics - CVE-2018-11061
Published: August 21, 2018 / Updated: August 22, 2018
RSA Security Analytics
Detailed vulnerability description
The vulnerability allows a remote authenticated 'Admin' or 'Operator' role attacker to gain elevated privileges on the target system.
The vulnerability exists due to a template engine configuration error. A remote attacker can inject a template and execute arbitrary commands on the target system with root privileges.