Vulnerability Details CVE-2018-1247
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.353
EPSS Ranking 96.8%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 5.8
Products affected by CVE-2018-1247
-
cpe:2.3:a:rsa:authentication_manager:-
-
cpe:2.3:a:rsa:authentication_manager:6.0
-
cpe:2.3:a:rsa:authentication_manager:6.1
-
cpe:2.3:a:rsa:authentication_manager:7.0
-
cpe:2.3:a:rsa:authentication_manager:7.1
-
cpe:2.3:a:rsa:authentication_manager:8.0
-
cpe:2.3:a:rsa:authentication_manager:8.1
-
cpe:2.3:a:rsa:authentication_manager:8.2
-
cpe:2.3:a:rsa:authentication_manager:8.3