RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104722 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2018/Jul/23 | third party advisory mailing list |
http://www.securitytracker.com/id/1041228 | vdb entry third party advisory |