RSA Authentication Manager Security Vulnerability CVE-2022-42003,CVE-2022-45047,CVE-2023-21894
Article Number
Applies To
RSA Version/Condition: 8.7 P4
CVE Identifier(s)
Article Summary
Description:
In FasterXML jackson-databind before 2.14.0-rc1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. Additional fix version in 2.13.4.1 and 2.12.17.1
Response: The flaw exists but cannot be exploited.
The RSA Authentication Manager does not use this feature. The setting "DeserializationFeature.UNWRAP_SINGLE_VALUE_ARRAYS" is required for the issues but not used in AM.
CVE-2022-45047:
Description:
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.
Response: No Impact on the Authentication Manager Version at all.
CVE-2023-21894 :
Description :
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Response: This is an attack by an attacker logged on to the OS against the Oracle Universal Installer (the embedded installer used to install the OPatch installer) - so no impact.
Resolution
Disclaimer
Related Articles
Cloud Access Service and Authenticators Historical Release Notes (November 2023 - November 2022) 393Number of Views Node secret mismatch: agent and server using different node secrets when authenticating from Citrix Web Interface 5.4 with… 740Number of Views RSA Customer Advisory: Spring Framework Spring4Shell Vulnerabilities CVE-2022-22965 CVE-2022-22950 CVE-2022-22963 185Number of Views RSA Authentication Manager Prime services fail to start after Java update on a Windows server: Error Failed creating java 299Number of Views Unable to install RSA Authentication Manager Web Tier on Microsoft Windows Server 238Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS
Don't see what you're looking for?