Description
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26522 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser. |
References
| Link | Providers |
|---|---|
| https://community.rsa.com/docs/DOC-111092 |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T03:43:40.798Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5340
No data.
Status : Modified
Published: 2020-03-26T13:15:13.517
Modified: 2024-11-21T05:33:56.570
Link: CVE-2020-5340
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD