RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.8.x and earlier
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 3.2.18
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
Component
spring-web version 5.3.22
RSA Response
Authentication Manager is not vulnerable because the product (OpenSAML service) doesn't use the readRemoteInvocation function of HttpInvokerServiceExporter in spring-web version 5.3.22.
- CVE-2018-11039
Link
https://nvd.nist.gov/vuln/detail/CVE-2018-11039
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use HiddenHttpMethodFilter of spring-web version 3.2.18.
- CVE-2020-5421
Link
https://nvd.nist.gov/vuln/detail/CVE-2020-5421
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product uses CSRF filters and provides Content-Disposition header in the response to mitigate this vulnerability.
- CVE-2022-22965
Link
https://nvd.nist.gov/vuln/detail/cve-2022-22965
Component
spring-beans version 3.2.18
RSA Response
The exploitation of this vulnerability is only possible with JRE 9 and above, and Apache Tomcat 9. Authentication Manager 8.7 SP1 is not vulnerable because the product doesn't use such combination of JRE and Tomcat with spring-beans version 3.2.18.
- CVE-2022-22970
Link
https://nvd.nist.gov/vuln/detail/CVE-2022-22970
Component
spring-beans version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use MultipartFile of spring-beans version 3.2.18.
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 122Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.31KNumber of Views Advisory regarding vulnerabilities reported by Oracle Java CVEs for applications running untrusted code 181Number of Views KCA Apache web server showing security vulnerability with scan due patch level/version 50Number of Views Best practices for running vulnerability scans against RSA Authentication Manager 8.x 1.09KNumber of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)