CVE-2018-11049 in EMC and Rsa Products
Published on July 11, 2018
RSA Identity Governance and Lifecycle Uncontrolled Search Path Vulnerability
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Products Associated with CVE-2018-11049
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-11049 are published in these products:
Affected Versions
Pivotal Operations Manager:- Version RSA(r) Identity Governance and Lifecycle version 7.1.0, all patch levels (Hardware Appliance, Software Bundle, and Virtual Application deployments only) is affected.
- Version RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (Hardware Appliance and Software Bundle (also known as Soft-Appliance) deployments only). is affected.
- Version RSA Via Lifecycle and Governance version 7.0, all patch levels (Hardware Appliance and Software Bundle (also known as Soft-Appliance) deployments only) is affected.
- Version RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (Hardware Appliance and Software Bundle (also known as Soft-Appliance) deployments only) is affected.
Exploit Probability
EPSS
0.05%
Percentile
15.52%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.