5 results (0.013 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. RSA Certificate Manager desde la versión 6.9 build 560 hasta la 6.9 build 564 contiene una vulnerabilidad de salto de directorio en los servidores RSA CMP Enroll y RSA REST Enroll. Un atacante remoto no autenticado podría explotar esta vulnerabilidad manipulando los parámetros de entrada de la aplicación para obtener acceso de lectura no autorizado a los archivos almacenados en el sistema de archivos del servidor, con los privilegios de la aplicación web en ejecución. • http://seclists.org/fulldisclosure/2018/Jul/11 http://www.securityfocus.com/bid/104674 http://www.securitytracker.com/id/1041211 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter. Vulnerabilidad de salto de directorio en EMC RSA OneStep 6.9 en versiones anteriores a build 559, tal como se utiliza en RSA Certificate Manager y RSA Registration Manager hasta la versión 6.9 build 558 y otros productos, permite a atacantes remotos leer archivos arbitrarios a través de un parámetro KCSOSC_ERROR_PAGE manipulado. • http://packetstormsecurity.com/files/133784/RSA-OneStep-6.9-Path-Traversal.html http://seclists.org/bugtraq/2015/Sep/135 http://www.securitytracker.com/id/1033671 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header. EMC RSA Certificate Manager (RCM) anterior a 6.9 build 558 y RSA Registration Manager (RRM) anterior a 6.9 build 558 permiten a atacantes remotos causar una denegación de servicio del servidor de administración a través de un mensaje de email MIME inválido con una cabecera de tipo de contenido multipart/*. • http://packetstormsecurity.com/files/130769/RSA-Digital-Certificate-Solution-XSS-Denial-Of-Service.html http://seclists.org/bugtraq/2015/Mar/47 http://www.securitytracker.com/id/1031912 • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote attackers to inject arbitrary web script or HTML via vectors related to the email address parameter. Vulnerabilidad de XSS en EMC RSA Certificate Manager (RCM) anterior a 6.9 build 558 y RSA Registration Manager (RRM) anterior a 6.9 build 558 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de vectores relacionados con el parámetro de la dirección de correo. • http://packetstormsecurity.com/files/130769/RSA-Digital-Certificate-Solution-XSS-Denial-Of-Service.html http://seclists.org/bugtraq/2015/Mar/47 http://www.securitytracker.com/id/1031912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.5EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the CMP shared secret parameter. Vulnerabilidad de XSS en EMC RSA Certificate Manager (RCM) anterior a 6.9 build 558 y RSA Registration Manager (RRM) anterior a 6.9 build 558 permite a usuarios remotos autenticados inyectar secuencias de comandos web arbitrarios o HTML a través de vectores relacionados con el parámetro CMP shared secret. • http://packetstormsecurity.com/files/130769/RSA-Digital-Certificate-Solution-XSS-Denial-Of-Service.html http://seclists.org/bugtraq/2015/Mar/47 http://www.securitytracker.com/id/1031912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •