RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.8.x and earlier
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 3.2.18
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
Component
spring-web version 5.3.22
RSA Response
Authentication Manager is not vulnerable because the product (OpenSAML service) doesn't use the readRemoteInvocation function of HttpInvokerServiceExporter in spring-web version 5.3.22.
- CVE-2018-11039
Link
https://nvd.nist.gov/vuln/detail/CVE-2018-11039
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use HiddenHttpMethodFilter of spring-web version 3.2.18.
- CVE-2020-5421
Link
https://nvd.nist.gov/vuln/detail/CVE-2020-5421
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product uses CSRF filters and provides Content-Disposition header in the response to mitigate this vulnerability.
- CVE-2022-22965
Link
https://nvd.nist.gov/vuln/detail/cve-2022-22965
Component
spring-beans version 3.2.18
RSA Response
The exploitation of this vulnerability is only possible with JRE 9 and above, and Apache Tomcat 9. Authentication Manager 8.7 SP1 is not vulnerable because the product doesn't use such combination of JRE and Tomcat with spring-beans version 3.2.18.
- CVE-2022-22970
Link
https://nvd.nist.gov/vuln/detail/CVE-2022-22970
Component
spring-beans version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use MultipartFile of spring-beans version 3.2.18.
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 122Number of Views Advisory regarding vulnerabilities reported by Oracle Java CVEs for applications running untrusted code 181Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.31KNumber of Views KCA Apache web server showing security vulnerability with scan due patch level/version 50Number of Views Spring-related vulnerabilities for RSA Authentication Manager 8.9 54Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators