Improper Authentication in RSA Identity Governance and Lifecycle Products
CVE-2019-18572

8.3HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
18 December 2019

Summary

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products before version 7.1.1 P03 expose a vulnerability due to the use of plain text password authentication in a Java JMX agent. This configuration allows an unauthenticated remote attacker to connect to the JMX agent, enabling them to monitor and manage the Java application, thus posing significant security risks to affected systems.

Affected Version(s)

RSA Identity Governance & Lifecycle < 7.1.0 P09, 7.1.1 P03

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.