CVE-2016-0918
RSA Identity Governance and Lifecycle Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
EMC RSA Identity Management and Governance en versiones anteriores a 6.8.1 P25 y 6.9.x en versiones anteriores a 6.9.1 P15 y RSA Via Lifecycle and Governance en versiones anteriores a 7.0.0 P04 permiten a usuarios remotos autenticados obtener información de User Detail Popup a través de una URL modificada.
RSA Identity Governance and Lifecycle is affected by an information disclosure vulnerability that potentially could be exploited by a malicious user to read certain details of other users in the system. RSA Identity Management and Governance versions prior to 6.8.1 P25 and 6.9.1 P15 are affected. Also affected are RSA Via Lifecycle and Governance versions prior to 7.0.0 P04.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-17 CVE Reserved
- 2016-09-23 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2016/Sep/52 | Mailing List |
|
http://www.securityfocus.com/bid/93108 | Vdb Entry | |
http://www.securitytracker.com/id/1036896 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Rsa Identity Management And Governance Search vendor "Emc" for product "Rsa Identity Management And Governance" | <= 6.8.1 Search vendor "Emc" for product "Rsa Identity Management And Governance" and version " <= 6.8.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Identity Management And Governance Search vendor "Emc" for product "Rsa Identity Management And Governance" | 6.9.0 Search vendor "Emc" for product "Rsa Identity Management And Governance" and version "6.9.0" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Identity Management And Governance Search vendor "Emc" for product "Rsa Identity Management And Governance" | 6.9.1 Search vendor "Emc" for product "Rsa Identity Management And Governance" and version "6.9.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Via Lifecycle And Governance Search vendor "Emc" for product "Rsa Via Lifecycle And Governance" | <= 7.0.0 Search vendor "Emc" for product "Rsa Via Lifecycle And Governance" and version " <= 7.0.0" | - |
Affected
|