VYPR
Medium severity6.1NVD Advisory· Published May 8, 2018· Updated Jun 17, 2026

CVE-2018-1248

CVE-2018-1248

Description

RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.

Affected products

3
  • cpe:2.3:a:rsa:authentication_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:rsa:authentication_manager:*:*:*:*:*:*:*:*range: <=8.3
    • (no CPE)range: <=8.3
  • Dell EMC/RSA Authentication Manager Security Console, Operation Console and Self-Service Consolev5
    Range: version 8.3 and earlier

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.