peter bassill · operator
$ cve CVE-2019-3759 JSON

CVE-2019-3759 EXPLOIT

6.4
MEDIUM · CVSS 3.1 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

Scoring

CVSS6.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS3.23% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2019-09-11
Last modified2026-06-17

Affected (2)

VendorProduct
dellrsa identity governance and lifecycle
dellrsa via lifecycle and governance

Public exploits

SourceTitleDate
exploit-dbRSA IG&L Aveksa 7.1.1 - Remote Code Execution2020-07-06

References

→ the Explorer  ·  watch your stack  ·  NVD