Information disclosure in RSA Identity Management and Governance - CVE-2016-0918

 

Information disclosure in RSA Identity Management and Governance - CVE-2016-0918

Published: September 24, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40090
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0918
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.


Affected software

RSA Identity Management and Governance

How to mitigate CVE-2016-0918

Install update from vendor's website.


External References

Related Security Bulletins