OpenSSL 3.x vulnerability announcement by Apache Software Foundation VP of Security
2 years ago
Article Number
000067990
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.7
Issue
Red Hat Distinguished Software Engineer and the Apache Software Foundation (ASF)'s VP of Security, on the week starting 24th of October tweeted, "OpenSSL 3.0.7 update to fix Critical CVE out next Tuesday 1300-1700UTC." 

Details are missing, but vulnerability is critical that will likely be abused to disclose server memory contents, and potentially reveal user details, and could be easily exploited remotely to compromise server private keys or execute code execute remotely.

 
Resolution
We do not use OpenSSL 3.x on either Authentication manager or Web-tier, and since 3.x is the only impacted version RSA is not impacted by this.