Is Via G&L vulnerable to “Authorization Bypass”?
Originally Published: 2016-08-30
Article Number
Applies To
RSA Versions: 6.9.1
Article Summary
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant.
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.
Resolution
The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
* If URL contains Request button ID then validate the button for the availability of the user
* Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
* Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements
The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)
Disclaimer
Related Articles
CERT/CC Vulnerability Note VU#475445: Potential Impact on RSA Products 31Number of Views How to set FILESYSTEMIO_OPTIONS for use with RSA Identity Governance and Lifecycle on a remote Oracle database where Autom… 35Number of Views enVision: How to delete the sftpagent's .pos / position file 41Number of Views Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA products 705Number of Views How to query a public database schema table for Segregation of Duties (SOD) violations in RSA Identity Governance & Lifecycle 98Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?