CVE-2020-5339
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
26/03/2020
Last modified:
30/09/2022
Description
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:* | 8.4 (excluding) | |
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:-:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p3:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p4:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p5:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p6:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p7:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p8:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:rsa_authentication_manager:8.4:p9:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



