RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.9.x
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 5.3.39
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
- CVE-2025-41249
Link
https://nvd.nist.gov/vuln/detail/CVE-2025-41249
Component
spring-core version 5.3.31 and 5.3.39
RSA Response
Authentication Manager is not vulnerable because the product doesn't use Spring Security's @EnableMethodSecurity feature.
- CVE-2024-38819
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38819
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
- CVE-2024-38816
Link
https://nvd.nist.gov/vuln/detail/CVE-2024-38816
Component
spring-webmvc version 5.3.30
RSA Response
Authentication Manager is not vulnerable because the product doesn't use WebMvc.fn and WebFlux.fn.
Related Articles
Spring-related vulnerabilities for RSA Authentication Manager 164Number of Views SecurID® Authentication Manager 8.7 Known Issues 197Number of Views Advisory regarding vulnerabilities reported by Oracle Java CVEs for applications running untrusted code 181Number of Views RSA Authentication Manager 8.9 Administrator's Guide 114Number of Views RSA Authentication Manager 8.9 Known Issues 229Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.4.3 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Enable SSH from a console connection if the Operations Console is not available for RSA Authentication Manager 8.x RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows