CVE-2019-18573
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-598
- Published
- 2019-12-18
- Last modified
- 2026-03-14
Affected products
- Dell RSA Identity Governance & Lifecycle
Weakness type
Related vulnerabilities
- CVE-2023-6014 — MLflow Authentication Bypass
- CVE-2021-36328 — Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may
- CVE-2020-5331 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2025-26473 — Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
- CVE-2022-22551 — DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a
- CVE-2021-21594 — Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerab
- CVE-2024-31206 — Use of Unencrypted HTTP Request in dectalk-tts