RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.9.x
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 5.3.39
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
- CVE-2025-41249
Link
https://nvd.nist.gov/vuln/detail/CVE-2025-41249
Component
spring-core version 5.3.31 and 5.3.39
RSA Response
Authentication Manager is not vulnerable because the product doesn't use Spring Security's @EnableMethodSecurity feature.
- CVE-2024-38819
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38819
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
- CVE-2024-38816
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
Related Articles
SecurID® Authentication Manager 8.7 Known Issues 194Number of Views RSA® Authentication Manager 8.7 SP1 Known Issues 254Number of Views Spring-related vulnerabilities for RSA Authentication Manager 138Number of Views RSA Authentication Manager 8.9 Known Issues 127Number of Views RSA Authentication Manager 8.9 Release Notes (January 2026) 347Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide