rsa CVE Vulnerabilities & Metrics

Focus on rsa vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About rsa Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with rsa. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total rsa CVEs: 58
Earliest CVE date: 01 Dec 1999, 05:00 UTC
Latest CVE date: 28 Mar 2023, 13:15 UTC

Latest CVE reference: CVE-2022-47529

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical rsa CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.95

Max CVSS: 10.0

Critical CVEs (≥9): 6

CVSS Range vs. Count

Range Count
0.0-3.9 23
4.0-6.9 60
7.0-8.9 13
9.0-10.0 6

CVSS Distribution Chart

Top 5 Highest CVSS rsa CVEs

These are the five CVEs with the highest CVSS scores for rsa, sorted by severity first and recency.

All CVEs for rsa

CVE-2022-47529 rsa vulnerability CVSS: 0 28 Mar 2023, 13:15 UTC

Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.

CVE-2022-37318 rsa vulnerability CVSS: 0 25 Aug 2022, 23:15 UTC

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-37317 rsa vulnerability CVSS: 0 25 Aug 2022, 23:15 UTC

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-37316 rsa vulnerability CVSS: 0 25 Aug 2022, 23:15 UTC

Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata to an authenticated user of the affected system. 6.10 P3 HF1 (6.10.0.3.1) is also a fixed release.

CVE-2021-33615 rsa vulnerability CVSS: 8.5 02 Jun 2022, 14:15 UTC

RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

CVE-2022-30585 rsa vulnerability CVSS: 4.0 26 May 2022, 20:15 UTC

The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to view sensitive information. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2022-30584 rsa vulnerability CVSS: 9.0 26 May 2022, 20:15 UTC

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2021-33616 rsa vulnerability CVSS: 3.5 04 Apr 2022, 12:15 UTC

RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

CVE-2021-38362 rsa vulnerability CVSS: 4.0 30 Mar 2022, 22:15 UTC

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

CVE-2022-26951 rsa vulnerability CVSS: 4.3 30 Mar 2022, 00:15 UTC

Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

CVE-2022-26950 rsa vulnerability CVSS: 5.8 30 Mar 2022, 00:15 UTC

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

CVE-2022-26949 rsa vulnerability CVSS: 4.0 30 Mar 2022, 00:15 UTC

Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra privileges.

CVE-2022-26948 rsa vulnerability CVSS: 5.0 30 Mar 2022, 00:15 UTC

The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.

CVE-2022-26947 rsa vulnerability CVSS: 3.5 30 Mar 2022, 00:15 UTC

Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

CVE-2021-41594 rsa vulnerability CVSS: 4.0 30 Mar 2022, 00:15 UTC

In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.

CVE-2021-29253 rsa vulnerability CVSS: 2.1 26 May 2021, 04:15 UTC

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.

CVE-2021-29252 rsa vulnerability CVSS: 3.5 26 May 2021, 04:15 UTC

RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.

CVE-2020-29538 rsa vulnerability CVSS: 4.0 29 Jan 2021, 07:15 UTC

Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.

CVE-2020-29537 rsa vulnerability CVSS: 4.9 29 Jan 2021, 07:15 UTC

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

CVE-2020-29536 rsa vulnerability CVSS: 4.0 29 Jan 2021, 07:15 UTC

Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.

CVE-2020-29535 rsa vulnerability CVSS: 3.5 29 Jan 2021, 07:15 UTC

Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.

CVE-2020-26884 rsa vulnerability CVSS: 4.3 18 Nov 2020, 16:15 UTC

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

CVE-2020-5384 rsa vulnerability CVSS: 7.2 31 Jul 2020, 18:15 UTC

Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability by using an alternate path to bypass authentication in order to gain full access to the system.

CVE-2020-5337 rsa vulnerability CVSS: 5.8 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.

CVE-2020-5336 rsa vulnerability CVSS: 5.8 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.

CVE-2020-5335 rsa vulnerability CVSS: 6.8 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the privileges of the authenticated victim user.

CVE-2020-5334 rsa vulnerability CVSS: 4.3 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is then executed by the web browser in the context of the vulnerable web application.

CVE-2020-5333 rsa vulnerability CVSS: 4.0 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.

CVE-2020-5332 rsa vulnerability CVSS: 9.0 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed.

CVE-2020-5331 rsa vulnerability CVSS: 2.1 04 May 2020, 19:15 UTC

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.

CVE-2019-3758 rsa vulnerability CVSS: 7.5 18 Sep 2019, 23:15 UTC

RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.

CVE-2019-3756 rsa vulnerability CVSS: 4.0 18 Sep 2019, 23:15 UTC

RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.

CVE-2019-3716 rsa vulnerability CVSS: 2.1 13 Mar 2019, 21:29 UTC

RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks.

CVE-2019-3715 rsa vulnerability CVSS: 2.1 13 Mar 2019, 21:29 UTC

RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.

CVE-2018-15780 rsa vulnerability CVSS: 4.0 03 Jan 2019, 21:29 UTC

RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could potentially exploit this vulnerability to bypass authorization checks and gain read access to restricted user information.

CVE-2018-11065 rsa vulnerability CVSS: 4.0 24 Aug 2018, 15:29 UTC

The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to read certain data. Embedded WorkPoint is upgraded to version 4.10.16, which contains a fix for the vulnerability.

CVE-2018-11060 rsa vulnerability CVSS: 6.5 24 Jul 2018, 19:29 UTC

RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their privileges.

CVE-2018-11059 rsa vulnerability CVSS: 3.5 24 Jul 2018, 19:29 UTC

RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.

CVE-2018-11049 rsa vulnerability CVSS: 6.9 11 Jul 2018, 20:29 UTC

RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

CVE-2018-1252 rsa vulnerability CVSS: 6.5 05 Jun 2018, 12:29 UTC

RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.

CVE-2018-1234 rsa vulnerability CVSS: 2.1 30 Mar 2018, 21:29 UTC

RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.

CVE-2018-1233 rsa vulnerability CVSS: 4.3 30 Mar 2018, 21:29 UTC

RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.

CVE-2018-1232 rsa vulnerability CVSS: 5.0 30 Mar 2018, 21:29 UTC

RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.

CVE-2018-1182 rsa vulnerability CVSS: 7.2 08 Mar 2018, 15:29 UTC

An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only). It allows certain OS level users to execute arbitrary scripts with root level privileges.

CVE-2017-14377 rsa vulnerability CVSS: 7.5 29 Nov 2017, 18:29 UTC

EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnerability that could potentially lead to authentication bypass.

CVE-2017-14372 rsa vulnerability CVSS: 4.3 11 Oct 2017, 19:29 UTC

RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

CVE-2017-14371 rsa vulnerability CVSS: 4.3 11 Oct 2017, 19:29 UTC

RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting via the request URL. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

CVE-2017-14370 rsa vulnerability CVSS: 3.5 11 Oct 2017, 19:29 UTC

RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

CVE-2017-14369 rsa vulnerability CVSS: 4.0 11 Oct 2017, 19:29 UTC

RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Archer user may potentially exploit this vulnerability to elevate their privileges and export certain application records.

CVE-2017-8005 rsa vulnerability CVSS: 3.5 17 Jul 2017, 14:29 UTC

The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple stored cross-site scripting vulnerabilities. Remote authenticated malicious users could potentially inject arbitrary HTML code to the application.

CVE-2017-8004 rsa vulnerability CVSS: 6.5 17 Jul 2017, 14:29 UTC

The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) allow an application administrator to upload arbitrary files that may potentially contain a malicious code. The malicious file could be then executed on the affected system with the privileges of the user the application is running under.

CVE-2017-5004 rsa vulnerability CVSS: 3.5 09 Jun 2017, 21:29 UTC

EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an affected system.

CVE-2017-5003 rsa vulnerability CVSS: 4.3 09 Jun 2017, 21:29 UTC

EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Reflected Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an affected system.

CVE-2016-0919 rsa vulnerability CVSS: 4.3 03 Feb 2017, 07:59 UTC

EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.

CVE-2015-6851 rsa vulnerability CVSS: 7.2 23 Dec 2015, 03:59 UTC

EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.

CVE-2015-4548 rsa vulnerability CVSS: 7.2 12 Oct 2015, 01:59 UTC

EMC RSA Web Threat Detection before 5.1 SP1 allows local users to obtain root privileges by leveraging access to a service account and writing commands to a service configuration file.

CVE-2015-4547 rsa vulnerability CVSS: 4.0 12 Oct 2015, 01:59 UTC

EMC RSA Web Threat Detection before 5.1 SP1 stores a cleartext AnnoDB password in a configuration file, which allows remote authenticated users to obtain sensitive information by reading this file.

CVE-2015-0541 rsa vulnerability CVSS: 6.8 05 Jun 2015, 10:59 UTC

Cross-site request forgery (CSRF) vulnerability in EMC RSA Web Threat Detection before 5.1 allows remote attackers to hijack the authentication of arbitrary users.

CVE-2014-4627 rsa vulnerability CVSS: 6.5 07 Nov 2014, 11:55 UTC

SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2013-3273 rsa vulnerability CVSS: 2.1 08 Jul 2013, 20:55 UTC

EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the cleartext administrative password from trace logging in custom SDK applications, which allows local users to obtain sensitive information by reading the trace log file.

CVE-2013-0947 rsa vulnerability CVSS: 2.1 07 Jun 2013, 20:55 UTC

EMC RSA Authentication Manager 8.0 before P1 allows local users to discover cleartext operating-system passwords, HTTP plug-in proxy passwords, and SNMP communities by reading a (1) log file or (2) configuration file.

CVE-2013-0941 rsa vulnerability CVSS: 2.1 22 May 2013, 13:29 UTC

EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.

CVE-2013-0931 rsa vulnerability CVSS: 5.4 05 Mar 2013, 22:03 UTC

EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.

CVE-2012-2280 rsa vulnerability CVSS: 5.0 13 Jul 2012, 21:55 UTC

EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability."

CVE-2012-2279 rsa vulnerability CVSS: 6.4 13 Jul 2012, 21:55 UTC

Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2012-2278 rsa vulnerability CVSS: 4.3 13 Jul 2012, 21:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2281 rsa vulnerability CVSS: 6.8 05 Jul 2012, 14:55 UTC

EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might allow remote attackers to conduct replay attacks via unspecified vectors.

CVE-2012-0403 rsa vulnerability CVSS: 6.3 20 Mar 2012, 15:55 UTC

Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.

CVE-2012-0402 rsa vulnerability CVSS: 9.3 20 Mar 2012, 15:55 UTC

EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.

CVE-2012-0401 rsa vulnerability CVSS: 6.5 20 Mar 2012, 15:55 UTC

Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2012-0400 rsa vulnerability CVSS: 7.9 20 Mar 2012, 15:55 UTC

EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVE-2012-0399 rsa vulnerability CVSS: 4.3 20 Mar 2012, 15:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-0397 rsa vulnerability CVSS: 7.6 06 Mar 2012, 23:55 UTC

Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

CVE-2011-4143 rsa vulnerability CVSS: 5.0 27 Jan 2012, 00:55 UTC

EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors.

CVE-2011-4141 rsa vulnerability CVSS: 9.3 17 Dec 2011, 03:54 UTC

Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file.

CVE-2011-2737 rsa vulnerability CVSS: 5.0 25 Aug 2011, 14:22 UTC

RSA enVision 3.x and 4.x before 4 SP4 P3 allows remote attackers to read arbitrary files via unspecified vectors, related to an "arbitrary file retrieval vulnerability."

CVE-2011-2736 rsa vulnerability CVSS: 5.0 25 Aug 2011, 14:22 UTC

RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to a recipient mailbox.

CVE-2011-0322 rsa vulnerability CVSS: 7.5 16 Mar 2011, 22:55 UTC

Unspecified vulnerability in EMC RSA Access Manager Server 5.5.x, 6.0.x, and 6.1.x allows remote attackers to access resources via unknown vectors.

CVE-2008-7266 rsa vulnerability CVSS: 4.3 26 Nov 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2010-3321 rsa vulnerability CVSS: 1.5 07 Oct 2010, 21:00 UTC

RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.

CVE-2010-3261 rsa vulnerability CVSS: 5.0 24 Sep 2010, 19:00 UTC

Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to read unspecified data via unknown vectors.

CVE-2010-3018 rsa vulnerability CVSS: 4.3 09 Sep 2010, 22:00 UTC

RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2010-3017 rsa vulnerability CVSS: 5.7 09 Sep 2010, 22:00 UTC

Unspecified vulnerability in RSA Access Manager Agent 4.7.1 before 4.7.1.7, when RSA Adaptive Authentication Integration is enabled, allows remote attackers to bypass authentication and obtain sensitive information via unknown vectors.

CVE-2010-2634 rsa vulnerability CVSS: 4.0 10 Aug 2010, 12:23 UTC

RSA enVision before 3.7 SP1 allows remote authenticated users to cause a denial of service via unspecified vectors.

CVE-2010-2337 rsa vulnerability CVSS: 6.0 28 Jul 2010, 12:48 UTC

Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

CVE-2008-6886 rsa vulnerability CVSS: 5.0 03 Aug 2009, 14:30 UTC

RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attackers to obtain the administrator password hash and conduct brute force guessing attacks.

CVE-2008-2027 rsa vulnerability CVSS: 5.8 30 Apr 2008, 14:10 UTC

Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such as Mozilla Firefox, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an ftp URL in the url parameter to a Redirect action.

CVE-2008-1470 rsa vulnerability CVSS: 4.3 24 Mar 2008, 22:44 UTC

Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.

CVE-2007-5703 rsa vulnerability CVSS: 4.3 29 Oct 2007, 22:46 UTC

Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-4900 rsa vulnerability CVSS: 4.3 14 Sep 2007, 18:17 UTC

Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field.

CVE-2007-2417 rsa vulnerability CVSS: 10.0 15 Jul 2007, 21:30 UTC

Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.

CVE-2006-4991 rsa vulnerability CVSS: 3.6 26 Sep 2006, 02:07 UTC

RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.

CVE-2005-4734 rsa vulnerability CVSS: 6.4 31 Dec 2005, 05:00 UTC

Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.

CVE-2005-3329 rsa vulnerability CVSS: 4.3 27 Oct 2005, 10:02 UTC

Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.

CVE-2005-1471 rsa vulnerability CVSS: 7.5 06 May 2005, 04:00 UTC

Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.

CVE-2005-1118 rsa vulnerability CVSS: 4.3 14 Apr 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.

CVE-2003-0389 rsa vulnerability CVSS: 4.3 24 Jul 2003, 04:00 UTC

Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.

CVE-2002-0507 rsa vulnerability CVSS: 2.1 12 Aug 2002, 04:00 UTC

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

CVE-2001-1462 rsa vulnerability CVSS: 7.5 24 Oct 2001, 04:00 UTC

WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.

CVE-2001-1461 rsa vulnerability CVSS: 7.5 22 Oct 2001, 04:00 UTC

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

CVE-2000-0522 rsa vulnerability CVSS: 5.0 08 Jun 2000, 04:00 UTC

RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.

CVE-1999-0834 rsa vulnerability CVSS: 10.0 01 Dec 1999, 05:00 UTC

Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.