Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False Positive
Originally Published: 2015-11-30
Article Number
Applies To
RSA Version/Condition: 6.0 / 6.1 / 6.2 SP3
CVE Identifier(s)
Article Summary
Originally reported as CVE-2015-4852.
A second, similar issue was reported as CVE-2015-6420
CVE-2015-4852 is actually a Weblogic CVE that is centered around Apache common libraries.
CVE-2015-6420 is a CISCO CVE centered around the same Apache common libraries.
These libraries are used in Access Manager from 6.0 up to 6.2 SP3.
The actual issue is a deserialization vulnerability involving Apache Commons collections, which is already being addressed by that group.
Link to Advisories
Alert Impact
Not Exploitable
Alert Impact Explanation
This is because of the following:
- Access Manager does not accept the input from the user to de-serialize the data.
- AxM runtime interfaces are not serializing any of the custom Java objects.
- Most of the references are associated with the Admin API, the methods for which are executed over the authentication.
Resolution
Disclaimer
Related Articles
Infineon Trusted Platform Module (TPM) Vulnerability (CVE-2017-15361) Impact on RSA Products 59Number of Views Speculative Execution Side-Channel Vulnerabilities (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646): Impact on RSA products 101Number of Views RSA Certificate Manager security vulnerabilities for Apache - False Positives (CVE-2011-3368 / CVE-2012-0053 / CVE-2013-18… 73Number of Views Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products 172Number of Views Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA products 711Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1
Don't see what you're looking for?