Medium severity4.8NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-8000
CVE-2017-8000
Description
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with an XSS payload) that could be executed when viewing or editing the assigned token profile in the token by another administrator's browser session.
Affected products
1- cpe:2.3:a:emc:rsa_authentication_manager:*:sp1:*:*:*:*:*:*Range: <=8.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- seclists.org/fulldisclosure/2017/Jul/25nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/99572nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038878nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.