Overview
The RSA KEON Registration Authority web interface contains multiple cross-site scripting (XSS) vulnerabilities.
Description
The RSA Keon Certificate Authority (CA) software is a digital certificate management system. The RSA KEON Registration Authority allows the CA to handle large numbers of certificate requests. The RSA KEON Registration Authority web interface contains multiple cross-site scripting vulnerabilities. |
Impact
An attacker may be able to obtain sensitive data from the site running the RSA KEON Registration Authority software or use the vulnerability create spoofed content. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to GamaSEC for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-5703 |
Severity Metric: | 0.97 |
Date Public: | 2007-10-26 |
Date First Published: | 2007-10-26 |
Date Last Updated: | 2007-11-14 20:34 UTC |
Document Revision: | 7 |