HIGH🇵🇱 Wersja polska

CVE-2014-0643

CVSS 7.6v2.0pub. 2014-05-16upd. 2026-05-06

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.

CVSS Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
  • Emc Rsa Netwitness

    APP
    Emc
    < 9.8.5.19
  • Emc Rsa Security Analytics

    APP
    Emc
    10.2 – 10.2.4 (excl.)10.3 – 10.3.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2018-11061CRITICAL9.1PL ✓same product

Server-Side Template Injection z wykonaniem kodu jako root w RSA NetWitness/Security Analytics

CVE-2016-8215MEDIUM6.1same product

EMC RSA Security Analytics 10.5.3 and 10.6.2 contains fixes for a Reflected Cross-Site Scripting vulnerability...

CVE-2013-6180MEDIUM6.8same product

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core...

CVE-2018-15764CRITICAL9.8PL ✓same vendor

RCE w Dell EMC ESRS Policy Manager przez niezabezpieczone usługi JMX

CVE-2018-1245CRITICAL9.0PL ✓same vendor

RSA Identity Lifecycle – bypass autoryzacji umożliwiający wykonanie poleceń OS