CVE-2018-11049

HIGH

EMC Rsa Identity Governance And Lifecycle - Uncontrolled Search Path

Title source: rule

Description

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

Scores

CVSS v3 7.3
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (4)

emc/rsa_identity_governance_and_lifecycle
emc/rsa_identity_management_and_governance
emc/rsa_identity_management_and_governance
rsa/rsa_via_lifecycle_and_governance

Timeline

Published Jul 11, 2018
Tracked Since Feb 18, 2026