Is Via G&L vulnerable to “Authorization Bypass”?
Originally Published: 2016-08-30
Article Number
Applies To
RSA Versions: 6.9.1
Article Summary
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant.
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.
Resolution
The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
* If URL contains Request button ID then validate the button for the availability of the user
* Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
* Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements
The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)
Disclaimer
Related Articles
DSA-2020-194: RSA MFA Agent for Microsoft Windows Authentication Bypass Vulnerability 28Number of Views How to bypass SSO for testing in RSA Identity Governance and Lifecycle 48Number of Views How to bypass RSA SecurID multiple domain authentication page 51Number of Views Preventing end users from bypassing the RSA SecurID Access Cloud Authentication Service 48Number of Views "Request Error" when editing a Global Role or viewing a Global Role in a Review in RSA Identity Governance & Lifecycle 123Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?