CVE-2019-18573: Dell Rsa Identity Governance And Lifecycle

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.

Affected products

  • Dell Rsa Identity Governance And Lifecycle: version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.1.0 only; version 7.1.1 only

Published 2019-12-18. Last modified 2026-06-17.