Permissions, Privileges, and Access Controls in RSA Identity Management and Governance - CVE-2015-0532

 

Permissions, Privileges, and Access Controls in RSA Identity Management and Governance - CVE-2015-0532

Published: May 1, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40800
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-0532
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: RSA
Affected software:
RSA Identity Management and Governance

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.


How to mitigate CVE-2015-0532

Install update from vendor's website.

Sources