Is Via G&L vulnerable to “Authorization Bypass”?
Originally Published: 2016-08-30
Article Number
Applies To
RSA Versions: 6.9.1
Article Summary
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant.
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.
Resolution
The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
* If URL contains Request button ID then validate the button for the availability of the user
* Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
* Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements
The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)
Disclaimer
Related Articles
Is Via G&L vulnerable to the “Strict Transport security misconfiguration” 28Number of Views DSA-2020-194: RSA MFA Agent for Microsoft Windows Authentication Bypass Vulnerability 29Number of Views How to bypass RSA SecurID multiple domain authentication page 51Number of Views How to bypass SSO for testing in RSA Identity Governance and Lifecycle 49Number of Views The URL parameter SSOLogin=false fails to bypass SSO login after upgrading to 7.0.2 of RSA Identity Governance & Lifecycle 131Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?