RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
BID:101605
Info
RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
| Bugtraq ID: | 101605 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-14373 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2017 12:00AM |
| Updated: | Dec 19 2017 09:00PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
EMC RSA Authentication Manager 6.1.5 EMC RSA Authentication Manager 8.2 SP1 Patch 4 EMC RSA Authentication Manager 8.2 SP1 Patch 2 EMC RSA Authentication Manager 8.2 SP1 Patch 1 EMC RSA Authentication Manager 8.2 SP1 EMC RSA Authentication Manager 8.2 EMC RSA Authentication Manager 8.1 Patch 6 EMC RSA Authentication Manager 8.1 EMC RSA Authentication Manager 8.0 EMC RSA Authentication Manager 7.1 EMC RSA Authentication Manager 6.1 |
| Not Vulnerable: |
EMC RSA Authentication Manager 8.2 SP1 Patch 5 |
Discussion
RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
RSA Authentication Manager is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to RSA Authentication Manager 8.2 SP1 patch 5 are vulnerable.
RSA Authentication Manager is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to RSA Authentication Manager 8.2 SP1 patch 5 are vulnerable.
Exploit / POC
RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
An attacker can exploit the issue by enticing an unsuspecting user to visit a specially crafted URL.
An attacker can exploit the issue by enticing an unsuspecting user to visit a specially crafted URL.
Solution / Fix
RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RSA Authentication Manager CVE-2017-14373 Cross Site Scripting Vulnerability
References:
References:
- ESA-2017-134: RSA® Authentication Manager Security Update for Reflected Cross-Si (Seclists.org)
- RSA Authentication Manager Home Page (EMC)
- RSA Homepage (RSA Security)