The IDR 12.22.0.0.37 release includes improvements to the IDR software upgrade process. It also features Tomcat upgrade and removal of no-company-specific URLs.
Tomcat Upgrade
IDR v12.22.0.0.37 now runs Tomcat v9.0.98, which includes a fix for the critical vulnerability identified as CVE-2024-56337.
Removal of Non-Company-Specific URLs from IDR
Access through non-company-specific URLs will soon be disabled. This change involves replacing the URLs used by the IDR to connect to the Software Update Repository and Adapter Update Repository with company-specific URLs. To ensure uninterrupted access, add the company-specific URL to your firewall's allow-list.
To determine if you are impacted, sign in to the Cloud Administration Console, navigate to Platform > Identity Router, and expand the Identity Router section to view the Status Indicators.
The Software Update Service/Adapter Update Service Status Indicator includes three statuses:
- The first two statuses check the IDR's connectivity through region-specific URLs.
- The newly introduced third status, Company Specific URL, verifies connectivity through the company-specific URL.
If the Company Specific URL status shows as healthy, no action is needed. However, if it is unhealthy, check your firewall rules to ensure the company-specific URL is included in the allow-list.
RSA recommends adding the wildcard access domain name (*.{baseAccessDomainName}.securid.com) to your firewall’s allow-list. If it is already listed, no further action is required. If not, you must add the company-specific URL to the allow-list to maintain uninterrupted access.
Company-specific URL format: companyName.{baseAccessDNSName}.securid.com
Company-specific URL format for GOV deployment: companyName.access.securidgov.com
Example: If the company name is rsa-dev in US deployment, then the company-specific URL will be: rsa-dev.access.securid.com.
Refer to the following table for baseAccessDNSName.
| Deployment | baseAccessDNSName |
| US | access |
| GOV | access |
| ANZ | access-anz |
| EMEA | access-eu |
| India | access-in |
| Japan | access-jp |
| Canada | access-ca |
| Singapore | access-sg |
Related Articles
How to upgrade an RSA SecurID Access IDR 355Number of Views Clarification on RSA Identity Router (IDR) Upgrade Notification (12.24.x) 28Number of Views Permanent Shutdown of Non-Company-Specific URLs 17Number of Views Clarification on RSA Identity Router (IDR) Upgrade Notification (12.22.0.0.37) 148Number of Views What to expect during an RSA SecurID Access Identity Router (IDR)/Cluster software update 628Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide