Security Advisory

CVE-2019-18573

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-18 20:50:14
Last updated 2024-09-16 16:28:49
Assigner dell
State PUBLISHED

Description

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.