Vulnerability triggers when accessing the following URL: https://<server-URL>/.htpasswd
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Apache Agent
RSA Version/Condition: 8.0.6
Test Environment: Red Hat Linux 8.10
CVE Identifier(s)
Article Summary
When accessing the following URL: https://<server-URL>/.htpasswd, it returns the main RSA Web Agent login page. This behavior triggers a vulnerability alert in security scans.
Alert Impact
Not Exploitable
Alert Impact Explanation
- The vulnerability scan incorrectly interprets the RSA Web Agent login page as exposure of sensitive files.
- In reality, the access is blocked and the page remains protected.
Resolution
This alert should be ignored as a false positive, since the observed behavior is expected.
Expected Behavior:
- Without Agent: Accessing https://<server-URL>/.htpasswd results in a 403 Forbidden error.
- With Agent: After RSA Web Agent authentication, accessing https://<server-URL>/.htpasswd also results in a 403 Forbidden error.
Disclaimer
Related Articles
When running PL/SQL block in RSA Identity Governance and Lifecycle, the following error occurs: ORA-01471: cannot create … 41Number of Views Inconsistencies between regular and bulk updates in account reviews for RSA Via Lifecycle and Governance 23Number of Views Which PKI credentials are stored on a RSA SecurID Smart Card 3100 and which standards does it follow? 17Number of Views RSA SecurID SDK 3.1 for Android Developer's Guide and Release Notes 75Number of Views RSA Identity Governance & Lifecycle installation fails with the following error: <install directory path>/staging/deploy/… 731Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?