CVE Vulnerabilities

CVE-2018-1182

Improper Privilege Management

Published: Mar 08, 2018 | Modified: Aug 06, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only). It allows certain OS level users to execute arbitrary scripts with root level privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Rsa_identity_governance_and_lifecycle Emc 7.0.1 (including) 7.0.1 (including)
Rsa_identity_governance_and_lifecycle Emc 7.0.2 (including) 7.0.2 (including)
Rsa_identity_management_and_governance Emc 6.9.0 (including) 6.9.0 (including)
Rsa_identity_management_and_governance Emc 6.9.1 (including) 6.9.1 (including)
Rsa_via_lifecycle_and_governance Rsa 7.0 (including) 7.0 (including)

Potential Mitigations

References