Executive brief
EMC RSA Security Analytics, a platform used for network monitoring and security forensics, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the web interface. If an administrative user clicks a specially crafted link, the attacker could potentially hijack their session or perform unauthorized actions within the management console. This could lead to a compromise of the monitoring system and the sensitive data it handles.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in EMC RSA Security Analytics versions 10.5.x and 10.6.x. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit this by tricking a user into clicking a malicious link or visiting a compromised website. Successful exploitation allows the attacker to execute arbitrary HTML or JavaScript code in the context of the victim's browser, potentially leading to session hijacking or unauthorized configuration changes. The issue is resolved in versions 10.5.3 and 10.6.2.
Affected products
- EMC RSA Security Analytics 10.5.x before 10.5.3, 10.6.x before 10.6.2
Timeline
- 2017-01-25: advisory: Initial NVD publication
- 2017-01-25: patched: Fixes available in versions 10.5.3 and 10.6.2