Improper Authentication in RSA Identity Governance and Lifecycle Products
CVE-2019-18572
8.3HIGH
Summary
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products before version 7.1.1 P03 expose a vulnerability due to the use of plain text password authentication in a Java JMX agent. This configuration allows an unauthenticated remote attacker to connect to the JMX agent, enabling them to monitor and manage the Java application, thus posing significant security risks to affected systems.
Affected Version(s)
RSA Identity Governance & Lifecycle < 7.1.0 P09, 7.1.1 P03
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved