SQL Injection Vulnerability in RSA Identity Governance and Lifecycle Software by RSA
CVE-2019-3760

6.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 September 2019

Summary

The RSA Identity Governance and Lifecycle software, along with RSA Via Lifecycle and Governance products, are susceptible to a SQL Injection flaw within Workflow Architect. This vulnerability permits a remote authenticated attacker to exploit the weakness by inputting specially crafted SQL commands, enabling unauthorized access to sensitive data stored within the back-end database. Effective remediation is essential to safeguard against potential data breaches.

Affected Version(s)

RSA Identity Governance and Lifecycle < 7.1.1 P02

RSA Identity Governance and Lifecycle < 7.1.0 P08

RSA Identity Governance and Lifecycle 7.0.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.