CVE-2020-5346: XSS
RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-5346?
CVE-2020-5346 is a stored cross-site scripting vulnerability in RSA Authentication Manager versions prior to 8.4 P11.
How does CVE-2020-5346 affect RSA Authentication Manager?
CVE-2020-5346 affects RSA Authentication Manager versions prior to 8.4 P11.
What is the severity of CVE-2020-5346?
CVE-2020-5346 has a severity rating of 4.8 (medium).
How can a malicious RSA Authentication Manager Security Console administrator exploit CVE-2020-5346?
A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit CVE-2020-5346 to store arbitrary HTML or JavaScript code.
Is there a fix for CVE-2020-5346?
The fix for CVE-2020-5346 is to upgrade RSA Authentication Manager to version 8.4 P11 or later.