RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8321 RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T18:03:34.741Z

Reserved: 2019-10-29T00:00:00

Link: CVE-2019-18574

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-03T21:15:10.940

Modified: 2024-11-21T04:33:19.537

Link: CVE-2019-18574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.