SQL Injection Vulnerability in RSA Identity Governance and Lifecycle Software by RSA
CVE-2019-3760
6.4MEDIUM
Summary
The RSA Identity Governance and Lifecycle software, along with RSA Via Lifecycle and Governance products, are susceptible to a SQL Injection flaw within Workflow Architect. This vulnerability permits a remote authenticated attacker to exploit the weakness by inputting specially crafted SQL commands, enabling unauthorized access to sensitive data stored within the back-end database. Effective remediation is essential to safeguard against potential data breaches.
Affected Version(s)
RSA Identity Governance and Lifecycle < 7.1.1 P02
RSA Identity Governance and Lifecycle < 7.1.0 P08
RSA Identity Governance and Lifecycle 7.0.2
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved