Vulnerabilities (CVE)

Filtered by vendor Rsa Subscribe
Filtered by product Authentication Agent For Web
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1233 1 Rsa 1 Authentication Agent For Web 2018-04-20 4.3 MEDIUM 6.1 MEDIUM
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
CVE-2018-1234 1 Rsa 1 Authentication Agent For Web 2018-04-20 2.1 LOW 5.5 MEDIUM
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.