CVE-2018-11051
Dashboard / Vulnerabilities / CVE-2018-11051
CVE-2018-11051
Published: 3 Jul 2018Last Modified: 10 Mar 2026
Summary:
Details: RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
References: , http://seclists.org/fulldisclosure/2018/Jul/11, http://www.securityfocus.com/bid/104674, http://www.securitytracker.com/id/1041211
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
