RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.8.x and earlier
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 3.2.18
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
Component
spring-web version 5.3.22
RSA Response
Authentication Manager is not vulnerable because the product (OpenSAML service) doesn't use the readRemoteInvocation function of HttpInvokerServiceExporter in spring-web version 5.3.22.
- CVE-2018-11039
Link
https://nvd.nist.gov/vuln/detail/CVE-2018-11039
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use HiddenHttpMethodFilter of spring-web version 3.2.18.
- CVE-2020-5421
Link
https://nvd.nist.gov/vuln/detail/CVE-2020-5421
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product uses CSRF filters and provides Content-Disposition header in the response to mitigate this vulnerability.
- CVE-2022-22965
Link
https://nvd.nist.gov/vuln/detail/cve-2022-22965
Component
spring-beans version 3.2.18
RSA Response
The exploitation of this vulnerability is only possible with JRE 9 and above, and Apache Tomcat 9. Authentication Manager 8.7 SP1 is not vulnerable because the product doesn't use such combination of JRE and Tomcat with spring-beans version 3.2.18.
- CVE-2022-22970
Link
https://nvd.nist.gov/vuln/detail/CVE-2022-22970
Component
spring-beans version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use MultipartFile of spring-beans version 3.2.18.
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 117Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.3KNumber of Views OpenSSL Heartbeat Vulnerability (Heartbleed) in RSA products 325Number of Views How to remediate the impact of the POODLE vulnerability on RSA Endpoint 234Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for Apache Struts 2 - False Positive 93Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager 8.9 Release Notes (January 2026) How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to…