vendor:
Authentication Manager
by:
Mantas Juskauskas (Office Vilnius)
6.1
CVSS
MEDIUM
XML External Entity Injection (XXE) & Cross-Site Scripting (XSS)
611, 79
CWE
Product Name: Authentication Manager
Affected Version From: RSA Authentication Manager 8.2.1.4.0-build1394922
Affected Version To: RSA Authentication Manager 8.2.1.4.0-build1394922 and earlier
Patch Exists: YES
Related CWE: CVE-2018-1247, CVE-2018-1248
CPE: a:rsa_security:authentication_manager
Other Scripts:
N/A
Platforms Tested: N/A
2017
XXE & XSS vulnerabilities
The used XML parser is resolving XML external entities which allows an authenticated attacker (or an attacker that is able to trick an authenticated user into importing malicious XML fils) to read arbitrary files from the server's file system. The web application is vulnerable to reflected XSS. An attacker can inject malicious JavaScript code into the application which is then executed in the context of the user's browser.
Mitigation:
Upgrade to version 8.3 P1 or later