XML External Entity injection in RSA Authentication Manager - CVE-2019-3768
Published: January 4, 2020 / Updated: July 17, 2020
RSA Authentication Manager
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.