Vulnerability triggers when accessing the following URL: https://<server-URL>/.htpasswd
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Apache Agent
RSA Version/Condition: 8.0.6
Test Environment: Red Hat Linux 8.10
CVE Identifier(s)
Article Summary
When accessing the following URL: https://<server-URL>/.htpasswd, it returns the main RSA Web Agent login page. This behavior triggers a vulnerability alert in security scans.
Alert Impact
Not Exploitable
Alert Impact Explanation
- The vulnerability scan incorrectly interprets the RSA Web Agent login page as exposure of sensitive files.
- In reality, the access is blocked and the page remains protected.
Resolution
This alert should be ignored as a false positive, since the observed behavior is expected.
Expected Behavior:
- Without Agent: Accessing https://<server-URL>/.htpasswd results in a 403 Forbidden error.
- With Agent: After RSA Web Agent authentication, accessing https://<server-URL>/.htpasswd also results in a 403 Forbidden error.
Disclaimer
Related Articles
Which PKI credentials are stored on a RSA SecurID Smart Card 3100 and which standards does it follow? 17Number of Views RSA Authentication Manager Web Tier installation fails with the following error: The directory already exists! 52Number of Views When running PL/SQL block in RSA Identity Governance and Lifecycle, the following error occurs: ORA-01471: cannot create … 41Number of Views This is a test solution 4Number of Views Sick error after successful login on /KMS key-manager.log shows 'com.chrysalisits.crypto.LunaException: LunaSession: slot… 20Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?