CVE Vulnerabilities

CVE-2018-1182

Improper Privilege Management

Published: Mar 08, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only). It allows certain OS level users to execute arbitrary scripts with root level privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Rsa_identity_governance_and_lifecycleEmc7.0.1 (including)7.0.1 (including)
Rsa_identity_governance_and_lifecycleEmc7.0.2 (including)7.0.2 (including)
Rsa_identity_management_and_governanceEmc6.9.0 (including)6.9.0 (including)
Rsa_identity_management_and_governanceEmc6.9.1 (including)6.9.1 (including)
Rsa_via_lifecycle_and_governanceRsa7.0 (including)7.0 (including)

Potential Mitigations

References