RSA AuthSDK C with AM 8.0 - ACM_OK (Passcode Accepted) returned inappropriately when passode field contains 257 or more characters.
Originally Published: 2014-01-17
Last Modified: 2023-09-22
Article Number
Applies To
Issue
Customer was not following our sample code and was able to enter a passcode of 257 random characters. They then found that when they called AceGetAuthenticationStatus it returned the response ACM_OK, indicating passcode accepted. If this were true this could be considered a vulnerability.
Cause
Resolution
Related Articles
Application of RSA Identity Governance & Lifecycle 7.0.2 patch 07 fails to start Aveksa Compliance Manager (ACM) for remot… 115Number of Views Random Rules are failing in RSA Governance & Lifecycle 266Number of Views ACM-100162 || PV_USER_ALL_ACCESS view does not include custom attributes post 7.1.1 installation 12Number of Views What happens to Access Fulfillment Express (AFX) during an Aveksa Compliance Manager (ACM) patch installation on a RSA Ide… 31Number of Views Patch or upgrade running long in step ACM-105090.sql in RSA Identity Governance & Lifecycle 91Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?