2020-11-10
11:50 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
RSA-2020-03
Please suggest if 8.3 P 03 is also affected ?
- Tags:
- Authenticator
- Authenticators
- Community Thread
- Discussion
- Forum Thread
- RSA SecurID
- RSA SecurID Access
- rsa-2020-03
- SecurID
- Token
- Token Auth
- Token Authentication
- Token Authenticator
- Token Authenticators
2 Replies
2020-11-11
02:16 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, as perRSA-2020-03 , RSA Authentication Manager 8.5 and earlier are the affected products.
2020-11-11
11:18 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, AM 8.3 is affected, and there is no patch for 8.3, only upgrade. RSA-2020-03 is written as if the only fix is to update all the way to AM 8.5, but on this discussion...
https://community.rsa.com/message/962123?commentID=962123&et=watches.email.thread#comment-962123
We determined that all of those vulnerabilities addressed in RSA-2020-03 have been remedied within AM 8.4 if you go to Patch 14. There will also be a hot fix for 8.4 P14 addressing the latest Oracle WebLogic vulnerability fixes from the Oracle WebLogic October 2020 CPU and the Oracle WebLogic Nov. 1 2020 hotfix
