4 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 0

23 Sep 2016 — EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL. EMC RSA Identity Management and Governance en versiones anteriores a 6.8.1 P25 y 6.9.x en versiones anteriores a 6.9.1 P15 y RSA Via Lifecycle and Governance en versiones anteriores a 7.0.0 P04 permiten a usuarios remotos autenticados obtener información de User Detail Popup a ... • http://seclists.org/bugtraq/2016/Sep/52 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

09 Sep 2015 — Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 7.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en EMC RSA Identity Management & Governance (IMG) en versiones anteriores a 7.0.0, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. RSA Identity Management and Governance contains fixes for cross site sc... • http://seclists.org/bugtraq/2015/Sep/36 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

09 Sep 2015 — Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x before 6.9.1 P6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en EMC RSA Identity Management & Governance (IMG) en versiones anteriores a 6.8.1 P18 y 6.9.x en versiones anteriores 6.9.1 P6, permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de v... • http://seclists.org/bugtraq/2015/Sep/36 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 2%CPEs: 5EXPL: 0

26 Aug 2014 — EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username. EMC RSA Identity Management and Governance (IMG) 6.5.x en versiones anteriores a 6.5.1 P11, 6.5.2 en versiones anteriores a P02HF01 y 6.8.x en versiones anteriores a 6.8.1 P07, cuando se utiliza Novell Identity Manager (también conocido como NovellIM), p... • http://archives.neohapsis.com/archives/bugtraq/2014-08/0133.html • CWE-287: Improper Authentication •