Vulnerability triggers when accessing the following URL: https://<server-URL>/.htpasswd
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Apache Agent
RSA Version/Condition: 8.0.6
Test Environment: Red Hat Linux 8.10
CVE Identifier(s)
Article Summary
When accessing the following URL: https://<server-URL>/.htpasswd, it returns the main RSA Web Agent login page. This behavior triggers a vulnerability alert in security scans.
Alert Impact
Not Exploitable
Alert Impact Explanation
- The vulnerability scan incorrectly interprets the RSA Web Agent login page as exposure of sensitive files.
- In reality, the access is blocked and the page remains protected.
Resolution
This alert should be ignored as a false positive, since the observed behavior is expected.
Expected Behavior:
- Without Agent: Accessing https://<server-URL>/.htpasswd results in a 403 Forbidden error.
- With Agent: After RSA Web Agent authentication, accessing https://<server-URL>/.htpasswd also results in a 403 Forbidden error.
Disclaimer
Related Articles
When running PL/SQL block in RSA Identity Governance and Lifecycle, the following error occurs: ORA-01471: cannot create … 41Number of Views Inconsistencies between regular and bulk updates in account reviews for RSA Via Lifecycle and Governance 23Number of Views Entitlement View does not scope correctly when triggered via request buttons in RSA Identity Governance & Lifecycle 16Number of Views When multi-step review is generated, NewReviewGeneratedEvent is triggered twice for second step review sending duplicate e… 49Number of Views Existing Role memberships later granted through Parent Roles are not revoked when the Role memberships are removed from th… 37Number of Views
Don't see what you're looking for?