- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
RSA Announces RSA Authentication Manager 8.7 Patch 2 and Updated Web-Tier Server
TS: 12.12.2022 11:35 CET
Hi,
I would like to better understand whether the RSA AM & Web Tier 8.7 Patch 2 is fixing security vulnerabilities affecting the RSA AM 8.6 or it applies only to 8.7.
From the Product Advisories notes reported at the link:
It is very clearly described that 8.6 is not affected by the announced vulnerabilities - see link:
However, the article about unaffected vulnerabilities was published on the 5th of December 2022, when RSA was referring as affected products to RSA AM 8.7 while today, the 12th of December 2022, as affected products RSA refers to RSA AM 8.7 Patch 1 and earlier.
How should we consider the version (and subversions) affected?
Thank you.
Kind regards,
Filippo Smedili
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
According to the RSA Authentication Manager 8.7 Patch 2 read me, RSA Authentication Manager 8.7 Patch 2 includes all fixes introduced in all versions 8.6 and 8.5 patches and security updates. In addition, the Patch 2 also contains fixes for the following issues.
- AM-47675: Updated Oracle WebLogic and Java components to prevent vulnerability issues.
- AM-47674: Updated SUSE Linux components used by RSA Authentication Manager to prevent potential
security vulnerabilities. - AM-46898: AMBA UUD functions accurately if no token is assigned to the user for DefLogin.
- AM-46286: Handling of the PIN history is now case sensitive.
Please review the readme for additional information.
,
Best regards,
Erica
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
TS: 14.12.2022 16:20 CET
Dear Erica, thank you for your feedback but I have to say that this does not clarify my doubts.
At the below reported link which has been posted on the 5th of December 2022, @utkarsh11 posted the following:
December 5, 2022
Summary
RSA announces RSA Authentication Manager 8.7 Patch 2. This patch (available here) contains important product updates. See the Readme for information about the contents of the patch.
An updated web-tier server (available here) is also available with Patch 2. See the web-tier server Readme for information on the updates to the web-tier server.
RSA recommends that you apply Patch 2 and deploy the updated web-tier server at the earliest opportunity.
Affected Products
- RSA Authentication Manager 8.7
- Web-Tier Server
Unaffected Products
- RSA Authentication Manager 8.6
- RSA Authentication Manager 8.5
- RSA Authentication Manager 8.4
- RSA Authentication Manager 8.3
For additional documentation, downloads, and more, visit the RSA Documentation and Downloads page on RSA Link.
On the 11th of December 2022, @utkarsh11 posted another article whose link and content are below reported:
December 5, 2022
RSA Identifier
RSA-2022-12
CVE Identifier
CVE-2020-36516, CVE-2022-2663, CVE-2022-36946, CVE-2021-46828, CVE-2022-40304, CVE-2022-40303, CVE-2022-32221, CVE-2022-40674, CVE-2022-0530, CVE-2022-0529, CVE-2022-1615, CVE-2022-29154, CVE-2020-28052, CVE-2022-23437, CVE-2022-22971, CVE-2020-17521, CVE-2022-21616, CVE-2021-29425
Severity
Critical
Severity Rating
See NVD (http://nvd.nist.gov/) for individual scores for each CVE
Affected Products
- RSA Authentication Manager 8.7 Patch 1 and earlier
- RSA Authentication Manager 8.7 web-tier server Patch 1 and earlier
Summary
Multiple components within RSA Authentication Manager require a security update to address various vulnerabilities
Details
Third-party components are updated for the following vulnerabilities:
- Linux Kernel
CVE-2020-36516, CVE-2022-2663, CVE-2022-36946 - libtirpc
CVE-2021-46828 - libxml2
CVE-2022-40304, CVE-2022-40303 - curl
CVE-2022-32221 - expat
CVE-2022-40674 - unzip
CVE-2022-0530, CVE-2022-0529 - samba
CVE-2022-1615 - rsync
CVE-2022-29154 - Oracle WebLogic
CVE-2020-28052, CVE-2022-23437, CVE-2022-22971, CVE-2020-17521, CVE-2022-21616, CVE-2021-29425
The update also resolves additional issues in components and features (such as log4j2, coherence, etc.) that do not impact the security of the Authentication Manager appliance and are not listed.
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.
Recommendation
The following RSA Authentication Manager releases contain resolutions to these vulnerabilities:
- RSA Authentication Manager 8.7 Patch 2 and later
- RSA Authentication Manager 8.7 Patch 2 web-tier server and later
RSA recommends all customers upgrade at the earliest opportunity.
For additional documentation, downloads and more, visit the RSA page.
Severity Rating
For an explanation of Severity Ratings, refer to the RSA Vulnerability Disclosure Policy. RSA recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.
EOPS Policy
RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.
Legal Information
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact RSA Technical Support. RSA Security LLC and its affiliates, including without limitation, distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information.
RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement.
In no event shall RSA, its affiliates, or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates, or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.
SUMMARY:
To make it short:
On 05.12.2022 it was stated that RSA AM 8.7 was affected while 8.6 was not affected.
On 12.12.2022 it was stated that RSA AM 8.7 Patch 1 and earlier were affected.
The question is:
For the vulnerabilities below listed, is the RSA AM 8.6 affected or it is not affected?
CVE Identifier
CVE-2020-36516, CVE-2022-2663, CVE-2022-36946, CVE-2021-46828, CVE-2022-40304, CVE-2022-40303, CVE-2022-32221, CVE-2022-40674, CVE-2022-0530, CVE-2022-0529, CVE-2022-1615, CVE-2022-29154, CVE-2020-28052, CVE-2022-23437, CVE-2022-22971, CVE-2020-17521, CVE-2022-21616, CVE-2021-29425
Severity
Critical
Thank you.
Kind regards,
Filippo Smedili
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Authentication Manager 8.7 patch 1 contains fixes up to 8.6 patch 4. Is that the information you need?
Best regards,
Erica
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No.
I need to know if 8.7.2 fixes vulnerabilities present in RSA AM 8.6 Patch 4 and if so, which vulnerabilities.
I didn´t think it would have been so hard to get such a feedback. The documentation/aarticles you have posted are unfortunately in contradiction and I am sure a clarification would be very helpful for several people.
Thank you.
Kind regards,
Filippo Smedili
