RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.9.x
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 5.3.39
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
- CVE-2025-41249
Link
https://nvd.nist.gov/vuln/detail/CVE-2025-41249
Component
spring-core version 5.3.31 and 5.3.39
RSA Response
Authentication Manager is not vulnerable because the product doesn't use Spring Security's @EnableMethodSecurity feature.
- CVE-2024-38819
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38819
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
- CVE-2024-38816
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
Related Articles
Spring-related vulnerabilities for RSA Authentication Manager 156Number of Views SecurID® Authentication Manager 8.7 Known Issues 197Number of Views RSA Authentication Manager 8.9 Known Issues 179Number of Views RSA® Authentication Manager 8.7 SP1 Known Issues 265Number of Views RSA Authentication Manager 8.9 Administrator's Guide 98Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators