CVE-2018-11049
HIGHRSA Identity Governance and Lifecycle - Uncontrolled Search Path Element via Environment Variable Manipulation
Title source: llmDescription
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104722
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jul/23
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1041228
Scores
CVSS v3
7.3
EPSS
0.0005
EPSS Percentile
15.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-427
Status
published
Products (4)
emc/rsa_identity_governance_and_lifecycle
7.1.0
emc/rsa_identity_management_and_governance
6.9.0
emc/rsa_identity_management_and_governance
6.9.1
rsa/rsa_via_lifecycle_and_governance
7.0
Published
Jul 11, 2018
Tracked Since
Feb 18, 2026