The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2019-12-18T20:50:14.868223Z

Updated: 2024-09-16T16:28:49.370Z

Reserved: 2019-10-29T00:00:00

Link: CVE-2019-18573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-18T21:15:13.083

Modified: 2024-11-21T04:33:19.420

Link: CVE-2019-18573

cve-icon Redhat

No data.