VYPR
High severity8.1NVD Advisory· Published Aug 22, 2016· Updated May 6, 2026

CVE-2016-0915

CVE-2016-0915

Description

The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference vulnerability."

Affected products

2
  • cpe:2.3:a:emc:authentication_manager_prime:3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:emc:authentication_manager_prime:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:authentication_manager_prime:3.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.