High severity8.1NVD Advisory· Published Aug 22, 2016· Updated May 6, 2026
CVE-2016-0915
CVE-2016-0915
Description
The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference vulnerability."
Affected products
2cpe:2.3:a:emc:authentication_manager_prime:3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:emc:authentication_manager_prime:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:emc:authentication_manager_prime:3.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- seclists.org/bugtraq/2016/Aug/71nvdMailing ListThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/92394nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1036557nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.