XML External Entity injection in RSA Authentication Manager - CVE-2019-3768

 

XML External Entity injection in RSA Authentication Manager - CVE-2019-3768

Published: January 4, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30457
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3768
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.


Affected software

RSA Authentication Manager

How to mitigate CVE-2019-3768

Install update from vendor's website.

RSA Authentication Manager - update to 8.4

External References

Related Security Bulletins