EMC RSA Authentication Manager is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible.
RSA Authentication Manager 8.2 SP1 Patch 5 and prior are vulnerable.
Information
EMC RSA Authentication Manager 8.2 SP1 Patch 4
EMC RSA Authentication Manager 8.2 SP1 Patch 2
EMC RSA Authentication Manager 8.2 SP1 Patch 1
EMC RSA Authentication Manager 8.2 SP1
EMC RSA Authentication Manager 8.2
Exploit
An attacker can exploit this issue using a web browser.
References: