Apache httpd vulnerability (CVE-2017-3167) in RSA Access Manager Apache 5.0.x Agent - False Positive
Originally Published: 2018-01-29
Article Number
Applies To
CVE Identifier(s)
Article Summary
A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd.
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
The function ap_get_basic_auth_pw() is used by the agent during the authentication phase only.
The password is retrieved from the HTTP Authorization header using this function to authenticate the user.
Disclaimer
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 118Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for Apache Struts 2 - False Positive 96Number of Views Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 45Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 88Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for OpenSSL - False Positive 200Number of Views
Trending Articles
How to download and install the AFX Server Archive in RSA Identity Governance & Lifecycle RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide The Template ({Connector Template Name}) has missing file content error when creating AFX Connectors in RSA Identity Gover… Downloading RSA Authentication Manager license files or RSA Software token seed records Troubleshooting RSA MFA Agent for Microsoft Windows
Don't see what you're looking for?