Host Header Injection in RSA Authentication Manager by RSA Security
CVE-2018-1248
6.1MEDIUM
What is CVE-2018-1248?
RSA Authentication Manager Security Console, Operation Console, and Self-Service Console versions 8.3 and earlier suffer from a host header injection vulnerability. This flaw enables remote attackers to poison the HTTP cache and potentially redirect users to malicious external sites. By exploiting this vulnerability, attackers can manipulate the traffic and compromise user interactions with the affected consoles.
Affected Version(s)
RSA Authentication Manager Security Console, Operation Console and Self-Service Console version 8.3 and earlier