Is Via G&L vulnerable to “Authorization Bypass”?
Originally Published: 2016-08-30
Article Number
Applies To
RSA Versions: 6.9.1
Article Summary
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant.
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.
Resolution
The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
* If URL contains Request button ID then validate the button for the availability of the user
* Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
* Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements
The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)
Disclaimer
Related Articles
RSA Identity G&L 7.1.0 installation intermittently fails on SLES 12 where 'Hardware Lock Elision' functionality of the CPU… 32Number of Views Is Via G&L vulnerable to the “Strict Transport security misconfiguration” 25Number of Views DSA-2020-194: RSA MFA Agent for Microsoft Windows Authentication Bypass Vulnerability 28Number of Views RSA Governance & Lifecycle Recipes: WF Node Metrics 14Number of Views How to bypass SSO for testing in RSA Identity Governance and Lifecycle 48Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?