RSA Authentication Manager Security Vulnerability CVE-2022-42003,CVE-2022-45047,CVE-2023-21894
Article Number
Applies To
RSA Version/Condition: 8.7 P4
CVE Identifier(s)
Article Summary
Description:
In FasterXML jackson-databind before 2.14.0-rc1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. Additional fix version in 2.13.4.1 and 2.12.17.1
Response: The flaw exists but cannot be exploited.
The RSA Authentication Manager does not use this feature. The setting "DeserializationFeature.UNWRAP_SINGLE_VALUE_ARRAYS" is required for the issues but not used in AM.
CVE-2022-45047:
Description:
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.
Response: No Impact on the Authentication Manager Version at all.
CVE-2023-21894 :
Description :
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Response: This is an attack by an attacker logged on to the OS against the Oracle Universal Installer (the embedded installer used to install the OPatch installer) - so no impact.
Resolution
Disclaimer
Related Articles
RSA Governance & Lifecycle Collections (Vol.16) : Amazon AWS IAM 32Number of Views RSA Authentication Manager 8.7 False Positive Security Vulnerabilities 134Number of Views Error when importing wildcard certificates to RSA Authentication Manager 8.x 516Number of Views Security vulnerabilities CVE-2020-14882, CVE-2020-14883 and CVE-2020-14750, others in WebLogic an internal component in We… 389Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 187Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?