CVE-2018-1247

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
08/05/2018
Last modified:
13/06/2018

Description

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:authentication_manager:*:*:*:*:*:*:*:* 8.3 (including)