CVE-2015-4546: Emc Rsa Certificate Manager

High severity, CVSS 7.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter.

Affected products

  • Emc Rsa Certificate Manager: up to and including 6.9
  • Emc Rsa Onestep: up to and including 6.9

Published 2015-10-02. Last modified 2026-06-17.