Loading
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.
Use CWE-427, Emc vendor hub and Rsa Identity Governance And Lifecycle product page to widen CVE-2018-11049 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-1245, CVE-2018-1182 and CVE-2017-8004 for nearby disclosures in the same product family.