PoC Index

CVE-2019-3759

HIGH 8.1EPSS 3.2%

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v3.1
6.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS v2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS
3.23% chance of exploitation in the next 30 days, 87th percentile
Published
2019-09-11
Updated
2024-09-17

ExploitDB entries (1)

References

Related