← Back to CVE List

CVE-2019-18573

Published: 2019-12-18T21:15Z
Last Modified: 2024-11-21T04:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt