RSA Authentication Manager before 8.7 SP2 Patch 1 allows...
Moderate severity
Unreviewed
Published
Feb 17, 2025
to the GitHub Advisory Database
•
Updated Feb 17, 2025
Description
Published by the National Vulnerability Database
Feb 17, 2025
Published to the GitHub Advisory Database
Feb 17, 2025
Last updated
Feb 17, 2025
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
References