RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.9.x
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 5.3.39
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
- CVE-2025-41249
Link
https://nvd.nist.gov/vuln/detail/CVE-2025-41249
Component
spring-core version 5.3.31 and 5.3.39
RSA Response
Authentication Manager is not vulnerable because the product doesn't use Spring Security's @EnableMethodSecurity feature.
- CVE-2024-38819
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38819
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
- CVE-2024-38816
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
Related Articles
SecurID® Authentication Manager 8.7 Known Issues 194Number of Views RSA® Authentication Manager 8.7 SP1 Known Issues 254Number of Views RSA Authentication Manager 8.9 Known Issues 103Number of Views Spring-related vulnerabilities for RSA Authentication Manager 135Number of Views RSA® Authentication Manager 8.5 Known Issues 67Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.8 Setup and Configuration Guide