« Volver al listado

CVE-2019-18573

Estado: ModificadaAlta (8.8)—

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Fuente: mapeo oficial MITRE CTID (CVE → ATT&CK).

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-18573",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "RSA Identity Governance & Lifecycle",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "7.1.0 P09, 7.1.1 P03",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-18T21:15:13.083",
  "references": [
    {
      "url": "https://community.rsa.com/docs/DOC-109310",
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://community.rsa.com/docs/DOC-109310",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-598"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session."
    },
    {
      "lang": "es",
      "value": "Los productos RSA Identity Governance and Lifecycle y RSA Via Lifecycle and Governance anteriores a 7.1.1 P03 contienen una vulnerabilidad de fijación de sesión. Un usuario local malintencionado autenticado podría aprovechar esta vulnerabilidad ya que el token de sesión se expone como parte de la URL. Un atacante remoto puede obtener acceso a la sesión de la víctima y realizar acciones arbitrarias con privilegios del usuario dentro de la sesión comprometida."
    }
  ],
  "lastModified": "2026-06-17T02:25:07.180",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54F243EB-5F06-4728-8815-93BDB5502F74"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD518D4A-157A-42D8-B958-8C4661CE6224"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2715882-4E9F-4E4C-A648-30B5D8B36C63"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC3F7997-46CC-4345-981A-4CA38A73BA8C"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD36DED8-5591-4A76-AD40-7DAED6EF1954"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CF203FD-8A59-4237-820A-FDBE4F28E4B9"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p03:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08FC40D4-433A-4EDE-87B1-422D0473D6D8"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p04:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CF1C39E-D12B-44E4-8172-CD91F17E871B"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p05:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31DCF79D-E1EA-4F65-B355-C821B0D78E73"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p06:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82CFC850-4C98-42B5-AE77-592FD64E78E1"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p07:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DE35E51-0C69-41A8-9332-A9E411CE0B92"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p08:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8989E78-229D-47B1-A60F-50394D8DF244"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E9E1900-FE59-440A-87D6-35DE7233EAB3"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15371ECD-CACD-4E1F-854B-D5EA6D1BBC54"
            },
            {
              "criteria": "cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACD868A6-05CC-4BCF-BC53-EA4418DE5F45"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}