XML Entity Injection Vulnerability in RSA Authentication Manager by Dell
CVE-2019-3768
6.5MEDIUM
What is CVE-2019-3768?
The RSA Authentication Manager, specifically versions before 8.4 P7, has an XML Entity Injection vulnerability that enables a remote authenticated attacker to exploit the system. By sending specially crafted XML messages, the attacker could gain unauthorized access to sensitive information stored in local system files, posing significant security risks to the affected systems.
Affected Version(s)
RSA Authentication Manager < 8.4 P7