CVE-2020-5340: XSS
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-5340?
CVE-2020-5340 is a stored cross-site scripting vulnerability in RSA Authentication Manager versions prior to 8.4 P10.
What is the severity of CVE-2020-5340?
The severity of CVE-2020-5340 is medium with a CVSS score of 4.8.
How does CVE-2020-5340 affect RSA Authentication Manager?
CVE-2020-5340 affects RSA Authentication Manager versions prior to 8.4 P10.
How can a malicious administrator exploit CVE-2020-5340?
A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit CVE-2020-5340 to store arbitrary HTML or JavaScript code.
Is there a fix available for CVE-2020-5340?
Yes, an update to RSA Authentication Manager version 8.4 P10 or higher addresses the vulnerability.