Vulnerability Details CVE-2018-1248
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2018-1248
-
cpe:2.3:a:rsa:authentication_manager:-
-
cpe:2.3:a:rsa:authentication_manager:6.0
-
cpe:2.3:a:rsa:authentication_manager:6.1
-
cpe:2.3:a:rsa:authentication_manager:7.0
-
cpe:2.3:a:rsa:authentication_manager:7.1
-
cpe:2.3:a:rsa:authentication_manager:8.0
-
cpe:2.3:a:rsa:authentication_manager:8.1
-
cpe:2.3:a:rsa:authentication_manager:8.2
-
cpe:2.3:a:rsa:authentication_manager:8.3