« Volver al listado

CVE-2017-15546

Estado: ModificadaMedia (4.3)—

The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-15546",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "EMC RSA Authentication Manager 8.2 SP1 P6 and earlier",
          "versions": [
            {
              "status": "affected",
              "version": "EMC RSA Authentication Manager 8.2 SP1 P6 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-01-25T03:29:00.227",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2018/Jan/81",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/102838",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1040268",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2018/Jan/81",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/102838",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1040268",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database."
    },
    {
      "lang": "es",
      "value": "Security Console en EMC RSA Authentication Manager 8.2 SP1 P6 y anteriores está afectado por una vulnerabilidad de inyección SQL ciega. Usuarios autenticados maliciosos podrían explotar esta vulnerabilidad para leer cualquier dato sin cifrar de la base de datos."
    }
  ],
  "lastModified": "2026-06-17T01:07:52.403",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8603D5EA-A79E-42F3-9007-79A9CE825ECA",
              "versionEndIncluding": "8.2"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A3C063C-76E1-443A-8BAE-FFC9C66DE925"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BA1672C-E2E7-4F52-8195-1C2714C41C6C"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72F1E8C7-631E-4279-B43B-5A300ECFBA26"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE00B3FD-710B-4876-B7C7-271A1C433E15"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9E7AE26-6DA9-4C65-B05F-F941A6386449"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72C1589D-CE78-421B-83AE-C02F8A4B648D"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1_p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9A4C535-24E9-4B94-9ED5-8884D752A2BE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}