CVE-2017-15546

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
25/01/2018
Last modified:
15/02/2018

Description

The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:* 8.2 (including)
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p1:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p2:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p3:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p4:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p5:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p6:*:*:*:*:*:*