MEDIUM🇵🇱 Wersja polska

CVE-2013-6180

CVSS 6.8v2.0pub. 2013-12-09upd. 2026-04-29

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent.

CVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
  • Emc Rsa Netwitness Nextgen

    APP
    Emc
    9.8
  • Emc Rsa Security Analytics

    APP
    Emc
    10.010.110.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-11061CRITICAL9.1PL ✓same product

Server-Side Template Injection z wykonaniem kodu jako root w RSA NetWitness/Security Analytics

CVE-2014-0643HIGH7.6same product

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Ker...

CVE-2016-8215MEDIUM6.1same product

EMC RSA Security Analytics 10.5.3 and 10.6.2 contains fixes for a Reflected Cross-Site Scripting vulnerability...

CVE-2018-15764CRITICAL9.8PL ✓same vendor

RCE w Dell EMC ESRS Policy Manager przez niezabezpieczone usługi JMX

CVE-2018-1245CRITICAL9.0PL ✓same vendor

RSA Identity Lifecycle – bypass autoryzacji umożliwiający wykonanie poleceń OS