Affected Products
- RSA Governance and Lifecycle version 8.0.0 P09 and version 8.0.0 P09 HF01
Unaffected Products
- RSA Governance and Lifecycle version 8.0.0 P08 and earlier
- RSA Governance and Lifecycle version 8.0.0 P10 and later
Summary
When creating or modifying a Role, there is a possibility of assigning values in an unexpected sequence, which could lead to an incorrect assignment or an exception concerning custom attributes.
Example:
- A value designated for Attribute1 can also be utilized for Attribute2, and vice versa, resulting in incorrect assignment.
- If Attribute1 is of String type while Attribute2 is of Number type, an error will be displayed on the user interface, and the modifications to the Role will not be saved.
Impact Conditions
There may be consequences if a customer is using version 8.0.0 P09, and/or version 8.0.0 P09 HF01, and if any of the following conditions is met under Admin > Attributes > Role.
- Multiple attribute separators for Roles, and the names of these separators are not arranged in ascending order.
- Attributes have been imported recently, and there is at least one attribute separator for the Role attributes.
Affected Roles
If Roles are created or Role Attributes are modified in relation to this issue, there is a possibility that the Role Attributes may be incorrectly assigned. The KB Article will assist in identifying all roles that have been created or edited following the implementation of version 8.0.0 P09, and 8.0.0 P09 HF01. It also includes instructions for the remediation that should be executed prior to correcting the values of the Role attributes.
Recommendation
RSA recommends that customers using the affected versions of RSA Governance & Lifecycle follow the guidelines provided in the KB Article to assess if they are impacted. If they are impacted, follow the remediation steps provided in the KB Article.
Related Articles
Role attributes are updated in wrong fields when creating or editing a role with separators in RSA Governance & Lifecycle 9Number of Views Device Settings for Risk-Based Authentication 9Number of Views Workflow Decision Node takes wrong path in SecurID Governance & Lifecycle 75Number of Views RSA Governance & Lifecycle Advanced Dashboards Library Release Notes - Revision 3.0 12Number of Views Timeout when editing a collector in RSA Governance & Lifecycle 148Number of Views
Trending Articles
RSA Authentication Manager Patch Updates RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Configuring a Checkpoint firewall to work with SecurID