Apache httpd vulnerability (CVE-2017-3167) in RSA Access Manager Apache 5.0.x Agent - False Positive
Originally Published: 2018-01-29
Article Number
Applies To
CVE Identifier(s)
Article Summary
A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd.
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
The function ap_get_basic_auth_pw() is used by the agent during the authentication phase only.
The password is retrieved from the HTTP Authorization header using this function to authenticate the user.
Disclaimer
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 123Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for Apache Struts 2 - False Positive 96Number of Views RSA Authentication Manager CVE-2016-0800 "DROWN" Vulnerability - False Positive 251Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 90Number of Views Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 45Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Authenticator 6.2.2 for Windows Administrator Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?