CVE-2018-11051
RSA Certificate Manager Path Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
RSA Certificate Manager desde la versión 6.9 build 560 hasta la 6.9 build 564 contiene una vulnerabilidad de salto de directorio en los servidores RSA CMP Enroll y RSA REST Enroll. Un atacante remoto no autenticado podría explotar esta vulnerabilidad manipulando los parámetros de entrada de la aplicación para obtener acceso de lectura no autorizado a los archivos almacenados en el sistema de archivos del servidor, con los privilegios de la aplicación web en ejecución.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-07-03 CVE Published
- 2023-11-24 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Jul/11 | Mailing List | |
http://www.securityfocus.com/bid/104674 | Third Party Advisory | |
http://www.securitytracker.com/id/1041211 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Rsa Certificate Manager Search vendor "Emc" for product "Rsa Certificate Manager" | <= 6.9 Search vendor "Emc" for product "Rsa Certificate Manager" and version " <= 6.9" | - |
Affected
|