Is Via G&L vulnerable to “Authorization Bypass”?
Originally Published: 2016-08-30
Article Number
Applies To
RSA Versions: 6.9.1
Article Summary
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant.
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.
Resolution
The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
* If URL contains Request button ID then validate the button for the availability of the user
* Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
* Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements
The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)
Disclaimer
Related Articles
Is Via G&L vulnerable to the “Strict Transport security misconfiguration” 28Number of Views RSA Identity G&L 7.1.0 installation intermittently fails on SLES 12 where 'Hardware Lock Elision' functionality of the CPU… 33Number of Views How to create and manage Entitlement Attributes through the User Interface in RSA Identity Governance & Lifecycle 59Number of Views False Positive - RSA Authentication Manager 8.1 SP1 P10 vulnerable to CVE 2016-0728, CVE-2015-8787 and CVE-2015-8709 (Open… 32Number of Views RSA Governance & Lifecycle 8.0 Patch 06 Release Notes 294Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?