Permissions, Privileges, and Access Controls in RSA Identity Management and Governance - CVE-2015-0532
Published: May 1, 2015 / Updated: August 9, 2020
RSA Identity Management and Governance
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.