Vulnerability record · CVE-2018-1247 · published 8 May 2018
CVE-2018-1247: Rsa authentication manager xml external entity (xxe) vulnerability
Rsa · Authentication Manager
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.
Description
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2018/May/18 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/104107 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040835 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44634/ | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2018/May/18 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/104107 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040835 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44634/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-1247 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1247), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.