CVE-2018-11049
HIGHEMC Rsa Identity Governance And Lifecycle - Uncontrolled Search Path
Title source: ruleDescription
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Scores
CVSS v3
7.3
EPSS
0.0005
EPSS Percentile
15.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (4)
emc/rsa_identity_governance_and_lifecycle
emc/rsa_identity_management_and_governance
emc/rsa_identity_management_and_governance
rsa/rsa_via_lifecycle_and_governance
Timeline
Published
Jul 11, 2018
Tracked Since
Feb 18, 2026