RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive
Originally Published: 2017-02-17
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
CVE Identifier(s)
Article Summary
The reported vulnerabilities discussed are:
- CVE-2016-9131
- CVE-2016-9147
- CVE-2016-9444
Link to Advisories
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9131
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9147
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9444
- https://kb.isc.org/article/AA-01439/74/CVE-2016-9131%3A-A-malformed-response-to-an-ANY-query-can-cause-an-assertion-failure-during-recursion.html
- https://kb.isc.org/article/AA-01440/74/CVE-2016-9147%3A-An-error-handling-a-query-response-containing-inconsistent-DNSSEC-information-could-cause-an-assertion-failure-.html
- https://kb.isc.org/article/AA-01441/74/CVE-2016-9444%3A-An-unusually-formed-DS-record-response-could-cause-an-assertion-failure.html
Alert Impact
Not Applicable
Alert Impact Explanation
-
CVE-2016-9131
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9147
Named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9444
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
Disclaimer
Related Articles
RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 58Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 81Number of Views RSA Subprocessor Information 167Number of Views OpenSSL Multiple Vulnerabilities in RSA products 603Number of Views Authentication Manager Log Messages (23001-23091) 35Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?