← Back

CVE-2015-0532

nvd nist
Published: May 1, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.

Affected (2)

1 product
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Version 6.9.0
Version 6.9.1

Related CWEs

References (6)

Timeline

No history available yet.