RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.9.x
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 5.3.39
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
- CVE-2025-41249
Link
https://nvd.nist.gov/vuln/detail/CVE-2025-41249
Component
spring-core version 5.3.31 and 5.3.39
RSA Response
Authentication Manager is not vulnerable because the product doesn't use Spring Security's @EnableMethodSecurity feature.
- CVE-2024-38819
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38819
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
- CVE-2024-38816
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
Related Articles
Spring-related vulnerabilities for RSA Authentication Manager 156Number of Views SecurID® Authentication Manager 8.7 Known Issues 197Number of Views RSA Authentication Manager 8.9 Known Issues 210Number of Views RSA Authentication Manager 8.9 Administrator's Guide 108Number of Views RSA Announces the Release of RSA Authentication Manager 8.9 18Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)