Vulnerability triggers when accessing the following URL: https://<server-URL>/.htpasswd
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Apache Agent
RSA Version/Condition: 8.0.6
Test Environment: Red Hat Linux 8.10
CVE Identifier(s)
Article Summary
When accessing the following URL: https://<server-URL>/.htpasswd, it returns the main RSA Web Agent login page. This behavior triggers a vulnerability alert in security scans.
Alert Impact
Not Exploitable
Alert Impact Explanation
- The vulnerability scan incorrectly interprets the RSA Web Agent login page as exposure of sensitive files.
- In reality, the access is blocked and the page remains protected.
Resolution
This alert should be ignored as a false positive, since the observed behavior is expected.
Expected Behavior:
- Without Agent: Accessing https://<server-URL>/.htpasswd results in a 403 Forbidden error.
- With Agent: After RSA Web Agent authentication, accessing https://<server-URL>/.htpasswd also results in a 403 Forbidden error.
Disclaimer
Related Articles
New feature for RSA Identity Governance & Lifecycle 7.1: Workflow System Status 302Number of Views Unable to access RSA SecurID Access Identity Router Console following initial deploy 78Number of Views RSA Authentication Manager Web Tier installation fails with the following error: The directory already exists! 51Number of Views Cloud Administration Authenticator Details API Version 2 191Number of Views AFX fails to create and/or update an Active Directory account with an 'Unparseable date' error in RSA Identity Governance … 296Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server RSA-2026-07: RSA Identity Router Security Update for Third-Party Component Vulnerabilities How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?