CVE-2020-5339: XSS
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5339?
The severity of CVE-2020-5339 is medium with a severity value of 4.8.
What is CVE-2020-5339?
CVE-2020-5339 is a stored cross-site scripting vulnerability in RSA Authentication Manager.
Which versions of RSA Authentication Manager are affected by CVE-2020-5339?
RSA Authentication Manager versions prior to 8.4 P10 are affected by CVE-2020-5339.
How does CVE-2020-5339 work?
A malicious RSA Authentication Manager Security Console administrator could exploit CVE-2020-5339 to store arbitrary HTML or JavaScript code in the Security Console.
Is there a fix for CVE-2020-5339?
Yes, upgrading RSA Authentication Manager to version 8.4 P10 or later fixes CVE-2020-5339.