CVE-2019-18573
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.
Los productos RSA Identity Governance and Lifecycle y RSA Via Lifecycle and Governance anteriores a 7.1.1 P03 contienen una vulnerabilidad de fijación de sesión. Un usuario local malintencionado autenticado podría aprovechar esta vulnerabilidad ya que el token de sesión se expone como parte de la URL. Un atacante remoto puede obtener acceso a la sesión de la víctima y realizar acciones arbitrarias con privilegios del usuario dentro de la sesión comprometida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-29 CVE Reserved
- 2019-12-18 CVE Published
- 2024-01-27 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
- CWE-598: Use of GET Request Method With Sensitive Query Strings
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://community.rsa.com/docs/DOC-109310 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.0.1 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.0.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.0.2 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.0.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p01 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p02 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p03 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p04 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p05 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p06 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p07 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.0 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.0" | p08 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.1 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.1 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.1" | p01 |
Affected
| ||||||
Dell Search vendor "Dell" | Rsa Identity Governance And Lifecycle Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" | 7.1.1 Search vendor "Dell" for product "Rsa Identity Governance And Lifecycle" and version "7.1.1" | p02 |
Affected
|