Vulnerability Description
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized access to that system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Authentication Manager | < 8.4 |
Related Weaknesses (CWE)
References
- https://seclists.org/fulldisclosure/2019/Jan/18Mailing ListThird Party Advisory
- https://seclists.org/fulldisclosure/2019/Jan/18Mailing ListThird Party Advisory
FAQ
What is CVE-2018-15782?
CVE-2018-15782 is a vulnerability with a CVSS score of 7.7 (HIGH). The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with...
How severe is CVE-2018-15782?
CVE-2018-15782 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15782?
Check the references section above for vendor advisories and patch information. Affected products include: Rsa Authentication Manager.