"product_name":"RSA Authentication Manager 8.2 SP1 and earlier",
"version":{
"version_data":[
{
"version_value":"RSA Authentication Manager 8.2 SP1 and earlier"
}
]
}
}
]
},
"vendor_name":"n/a"
}
]
}
},
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with an XSS payload) that could be executed when viewing or editing the assigned token profile in the token by another administrator's browser session."