Информационная безопасность
[RU] switch to English


Многочисленные уязвимости безопасности в EMC RSA Certificate Manager / Registration Manager
Опубликовано:16 марта 2015 г.
Источник:
SecurityVulns ID:14313
Тип:удаленная
Уровень опасности:
5/10
Описание:Межсайтовый сркиптинг, DoS.
Затронутые продукты:EMC : RSA Certificate Manager 6.9
 EMC : RSA Registration Manager 6.9
CVE:CVE-2015-0523 (EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header.)
 CVE-2015-0522 (Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote attackers to inject arbitrary web script or HTML via vectors related to the email address parameter.)
 CVE-2015-0521 (Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the CMP shared secret parameter.)
 CVE-2014-0231 (The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.)
Оригинальный текстdocumentEMC, ESA-2015-014: RSA® Digital Certificate Solution Multiple Vulnerabilities (16.03.2015)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород