Description
RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product. A remote authenticated malicious RSA NetWitness Server user with an Admin or Operator role could exploit this vulnerability to execute arbitrary commands on the server with root privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-3105 | RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product. A remote authenticated malicious RSA NetWitness Server user with an Admin or Operator role could exploit this vulnerability to execute arbitrary commands on the server with root privileges. |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T01:06:59.417Z
Reserved: 2018-05-14T00:00:00.000Z
Link: CVE-2018-11061
No data.
Status : Modified
Published: 2018-08-24T15:29:00.373
Modified: 2024-11-21T03:42:36.000
Link: CVE-2018-11061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD