Back to search
CVE-2015-0532
Published: May 1, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150429 ESA-2015-078: RSA Identity Management and Governance (IMG) Insecure Password Reset Vulnerability
mailing-list
x_refsource_BUGTRAQ
1032218
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now