RSA AuthSDK C with AM 8.0 - ACM_OK (Passcode Accepted) returned inappropriately when passode field contains 257 or more characters.
Originally Published: 2014-01-17
Article Number
Applies To
Issue
Customer was not following our sample code and was able to enter a passcode of 257 random characters. They then found that when they called AceGetAuthenticationStatus it returned the response ACM_OK, indicating passcode accepted. If this were true this could be considered a vulnerability.
Cause
Resolution
Related Articles
Insufficient translation of request button name in request forms in RSA Identity Governance & Lifecycle 11Number of Views RSA Authentication Agent 8.0 for Web for Internet Information Services Generates HTTP Error 500.21 25Number of Views Token Import Not Showing Security Domain Dropdown in the RSA Authentication Manager 8.x 26Number of Views RSA Announces the Availability of RSA Authentication Agent API 8.1 Service Pack 3 for C and Java 2Number of Views Pop up blocker displays when downloading multiple files from myRSA 25Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA-2026-10: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide RSA SecurID Software Token 4.2.1 for Mac OS X Administrator's Guide
Don't see what you're looking for?