RSA-2026-03: RSA Governance and Lifecycle Security Update for Oracle Database Vulnerabilities
14 days ago

RSA-2026-03: RSA Governance and Lifecycle Security Update for Oracle Database Vulnerabilities

 

RSA Identifier: RSA-2026-03

 

CVE Identifier: See Advisory

 

Severity: Critical

 

Severity Rating: See NVD (https://nvd.nist.gov) for individual scores for each CVE

 

Affected products (all versions)

  • RSA Governance and Lifecycle
  • SecurID Governance and Lifecycle

 

Note: This applies only to RSA Governance & Lifecycle deployment using an RSA-provided Oracle 19c database.

 

Unaffected Products

  • RSA Governance and Lifecycle and SecurID Governance and Lifecycle:
    Software-only systems or any deployment where RSA did not provide the database.

 

Summary

The database components in RSA Governance and Lifecycle and SecurID Governance and Lifecycle require a security update to address various vulnerabilities.

 

Details

RSA Governance and Lifecycle and SecurID Governance and Lifecycle have been updated to address the following security vulnerabilities.

 

Oracle 19.30.0.0 Updates 

CVE-2021-2341

CVE-2021-2369

CVE-2021-2388

CVE-2021-2432

CVE-2021-35550

CVE-2021-35556

CVE-2021-35559

CVE-2021-35561

CVE-2021-35564

CVE-2021-35565

CVE-2021-35567

CVE-2021-35578

CVE-2021-35586

CVE-2021-35588

CVE-2021-35603

CVE-2022-21248

CVE-2022-21277

CVE-2022-21282

CVE-2022-21283

CVE-2022-21291

CVE-2022-21293

CVE-2022-21294

CVE-2022-21296

CVE-2022-21299

CVE-2022-21305

CVE-2022-21340

CVE-2022-21341

CVE-2022-21349

CVE-2022-21360

CVE-2022-21365

CVE-2022-21366

CVE-2022-21426

CVE-2022-21434

CVE-2022-21443

CVE-2022-21449

CVE-2022-21476

CVE-2022-21496

CVE-2022-21540

CVE-2022-21541

CVE-2022-21549

CVE-2022-21618

CVE-2022-21619

CVE-2022-21624

CVE-2022-21626

CVE-2022-21628

CVE-2022-34169

CVE-2022-39399

CVE-2023-21830

CVE-2023-21835

CVE-2023-21843

CVE-2023-21930

CVE-2023-21937

CVE-2023-21938

CVE-2023-21939

CVE-2023-21954

CVE-2023-21967

CVE-2023-21968

CVE-2024-20918

CVE-2024-20919

CVE-2024-20921

CVE-2024-20926

CVE-2024-20932

CVE-2024-20945

CVE-2024-20952

CVE-2024-21011

CVE-2024-21012

CVE-2024-21068

CVE-2024-21085

CVE-2024-21094

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

CVE-2025-21502

CVE-2025-21587

CVE-2025-30691

CVE-2025-30698

CVE-2025-30749

CVE-2025-30754

CVE-2025-30761

CVE-2025-50059

CVE-2025-50106

CVE-2025-53057

CVE-2025-53066

CVE-2025-61748

CVE-2026-21925

CVE-2026-21932

CVE-2026-21933

CVE-2026-21945

  

Note: For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here consult the National Vulnerability Database (NVD) at https://nvd.nist.gov. To search for a CVE, use the database's search utility at https://nvd.nist.gov/vuln/search.

 

Recommendation

The Appliance Updater tool's February 2026 release will resolve these issues.

RSA recommends all customers install the Appliance Updater to ensure that embedded database components are kept current with security updates and patches. 

This Appliance Updater supports the RSA Governance and Lifecycle or SecurID Governance and Lifecycle products which use an RSA-provided Oracle 19c database. 

Customers can download the Appliance Updater from here. The product documentation and software are available on RSA Governance and Lifecycle space of RSA Community.

 

Severity Rating

For an explanation of Severity Ratings, refer to the Security Advisories Severity Rating knowledge base article. RSA recommends all customers consider both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with security vulnerability.

Legal Information

Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact RSA Technical Support. RSA Security LLC and its affiliates, including without limitation, distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title, and non-infringement. In no event shall RSA, its affiliates, or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits, or special damages, even if RSA, its affiliates, or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.

Announcement