Code Injection in RSA Via Lifecycle and Governance and RSA Identity Governance and Lifecycle - CVE-2019-3759
Published: September 11, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote authenticated user to read and manipulate data.
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.
Affected software
RSA Identity Governance and Lifecycle