CVE-2019-3768

MEDIUM

RSA Authentication Manager < 8.4 P7 - Authenticated XML External Entity Injection

Title source: llm
STIX 2.1

Description

RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.

Scores

CVSS v3 6.5
EPSS 0.0050
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (2)
emc/rsa_authentication_manager 8.4 (7 CPE variants)
emc/rsa_authentication_manager < 8.4
Published Jan 03, 2020
Tracked Since Feb 18, 2026