Vulnerability triggers when accessing the following URL: https://<server-URL>/.htpasswd
Last Modified: 2026-05-08
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Apache Agent
RSA Version/Condition: 8.0.6
Test Environment: Red Hat Linux 8.10
CVE Identifier(s)
Article Summary
When accessing the following URL: https://<server-URL>/.htpasswd, it returns the main RSA Web Agent login page. This behavior triggers a vulnerability alert in security scans.
Alert Impact
Not Exploitable
Alert Impact Explanation
- The vulnerability scan incorrectly interprets the RSA Web Agent login page as exposure of sensitive files.
- In reality, the access is blocked and the page remains protected.
Resolution
This alert should be ignored as a false positive, since the observed behavior is expected.
Expected Behavior:
- Without Agent: Accessing https://<server-URL>/.htpasswd results in a 403 Forbidden error.
- With Agent: After RSA Web Agent authentication, accessing https://<server-URL>/.htpasswd also results in a 403 Forbidden error.
Disclaimer
Related Articles
Error 'Bad Gateway' when accessing the appliance URLs 56Number of Views RSA Authentication Manager 8.2 Multiple OpenSSL Vulnerabilities - False Positive 73Number of Views Qualys Enterprise TruRisk - SAML My Page SSO Configuration - RSA Ready Implementation Guide 8Number of Views Spring-related vulnerabilities for RSA Authentication Manager 174Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 191Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?