CVE-2015-0532

Severity

75%

Complexity

99%

Confidentiality

106%

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.

CVSS 2.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).

Overview

Type

EMC RSA Identity Management and Governance (IMG)

First reported 9 years ago

2015-05-01 10:59:00

Last updated 8 years ago

2016-04-01 01:05:00

Affected Software

EMC RSA Identity Management and Governance (IMG) 6.9.0

6.9.0

EMC RSA Identity Management and Governance (IMG) 6.9.1

6.9.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.