CVE-2019-18574: XSS
RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18574?
The severity of CVE-2019-18574 is medium.
Which software versions are affected by CVE-2019-18574?
RSA Authentication Manager software versions prior to 8.4 P8 are affected by CVE-2019-18574.
What is the CWE ID associated with CVE-2019-18574?
The CWE ID associated with CVE-2019-18574 is 79.
How can a malicious Security Console administrator exploit CVE-2019-18574?
A malicious Security Console administrator could exploit CVE-2019-18574 by storing arbitrary HTML or JavaScript code through the web interface.
Is there a reference link for CVE-2019-18574?
Yes, you can find more information about CVE-2019-18574 at this link: https://www.dell.com/support/security/en-us/details/DOC-109297/DSA-2019-168-RSA®-Authentication-Manager-Software-Stored-Cross-Site-Scripting-Vulnerability