CVE Published: 17/07/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: dell |
Vendor: n/a |
Product: RSA Authentication Manager 8.2 SP1 and earlier Status : PUBLISHED
CVE-2017-8000 Description
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with an XSS payload) that could be executed when viewing or editing the assigned token profile in the token by another administrator\'s browser session.