MEDIUM · 6.8

CVE-2013-6180

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended ...

Vulnerability Description

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
EmcRsa Netwitness Nextgen9.8
EmcRsa Security Analytics10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6180?

CVE-2013-6180 is a vulnerability with a CVSS score of 6.8 (MEDIUM). EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended ...

How severe is CVE-2013-6180?

CVE-2013-6180 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-6180?

Check the references section above for vendor advisories and patch information. Affected products include: Emc Rsa Netwitness Nextgen, Emc Rsa Security Analytics.