RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
BID:66461
Info
RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
| Bugtraq ID: | 66461 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2014-0623 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2014 12:00AM |
| Updated: | Mar 26 2014 12:00AM |
| Credit: | Dave Morgan |
| Vulnerable: |
RSA Security Authentication Manager 7.1 |
| Not Vulnerable: |
RSA Security Authentication Manager 6.1 |
Discussion
RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
RSA Authentication Manager is prone to a cross-frame scripting vulnerability.
Successful exploits will allow attackers to bypass the same-origin policy and perform unauthorized actions; other attacks are possible.
RSA Authentication Manager 7.1 is vulnerable.
RSA Authentication Manager is prone to a cross-frame scripting vulnerability.
Successful exploits will allow attackers to bypass the same-origin policy and perform unauthorized actions; other attacks are possible.
RSA Authentication Manager 7.1 is vulnerable.
Exploit / POC
RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
Attackers can exploit this issue by tricking an unsuspecting victim into visiting a malicious web page.
Attackers can exploit this issue by tricking an unsuspecting victim into visiting a malicious web page.
Solution / Fix
RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RSA Authentication Manager CVE-2014-0623 Cross Frame Scripting Vulnerability
References:
References:
- EMC Homepage (EMC)