EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.
CVSS Vector
AV:N/AC:H/Au:N/C:C/I:C/A:CEmc Rsa Netwitness
APPEmc< 9.8.5.19Emc Rsa Security Analytics
APPEmc10.2 – 10.2.4 (excl.)10.3 – 10.3.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2018-11061CRITICAL9.1PL ✓same product
Server-Side Template Injection z wykonaniem kodu jako root w RSA NetWitness/Security Analytics
CVE-2016-8215MEDIUM6.1same product
EMC RSA Security Analytics 10.5.3 and 10.6.2 contains fixes for a Reflected Cross-Site Scripting vulnerability...
CVE-2013-6180MEDIUM6.8same product
EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core...
CVE-2018-15764CRITICAL9.8PL ✓same vendor
RCE w Dell EMC ESRS Policy Manager przez niezabezpieczone usługi JMX
CVE-2018-1245CRITICAL9.0PL ✓same vendor
RSA Identity Lifecycle – bypass autoryzacji umożliwiający wykonanie poleceń OS