RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.8.x and earlier
- CVE-2016-1000027
Link
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
Component
spring-web version 3.2.18
RSA Response
Authentication Manager uses the readRemoteInvocation function from the Spring interface HttpInvokerServiceExporter, which can potentially allow deserialization of untrusted objects if the endpoints are exposed to untrusted clients. As per CVE-2016-1000027, any interface that permits deserialization of objects from untrusted clients may be impacted. However, Authentication Manager restricts access to the HttpInvokerServiceExporter service to only trusted and authenticated clients, hence, there is no impact on Authentication Manager due to this CVE.
Component
spring-web version 5.3.22
RSA Response
Authentication Manager is not vulnerable because the product (OpenSAML service) doesn't use the readRemoteInvocation function of HttpInvokerServiceExporter in spring-web version 5.3.22.
- CVE-2018-11039
Link
https://nvd.nist.gov/vuln/detail/CVE-2018-11039
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use HiddenHttpMethodFilter of spring-web version 3.2.18.
- CVE-2020-5421
Link
https://nvd.nist.gov/vuln/detail/CVE-2020-5421
Component
spring-web version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product uses CSRF filters and provides Content-Disposition header in the response to mitigate this vulnerability.
- CVE-2022-22965
Link
https://nvd.nist.gov/vuln/detail/cve-2022-22965
Component
spring-beans version 3.2.18
RSA Response
The exploitation of this vulnerability is only possible with JRE 9 and above, and Apache Tomcat 9. Authentication Manager 8.7 SP1 is not vulnerable because the product doesn't use such combination of JRE and Tomcat with spring-beans version 3.2.18.
- CVE-2022-22970
Link
https://nvd.nist.gov/vuln/detail/CVE-2022-22970
Component
spring-beans version 3.2.18
RSA Response
Authentication Manager is not vulnerable because the product doesn't use MultipartFile of spring-beans version 3.2.18.
Related Articles
Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 117Number of Views OpenSSL Heartbeat Vulnerability (Heartbleed) in RSA products 325Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.3KNumber of Views RSA Authentication Manager 8.x Security Vulnerabilities for Apache Struts 2 - False Positive 93Number of Views KCA Apache web server showing security vulnerability with scan due patch level/version 45Number of Views
Trending Articles
RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Release Notes for RSA Authentication Manager 8.8 How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.9 Release Notes (January 2026)