EMC RSA Authentication Agent for Web dla Apache Web Server w wersji 8.0 oraz 8.0.1 przed build 618 zawiera podatność umożliwiającą ominięcie uwierzytelnienia. Ze względu na krytyczny wynik CVSS 9.8 i brak wymagań wstępnych, podatność stanowi poważne zagrożenie dla chronionych zasobów webowych.
▸ Pokaż oryginał (EN)
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnerability that could potentially lead to authentication bypass.
Podatność sklasyfikowana jako CWE-287 (Improper Authentication) wskazuje na nieprawidłową implementację mechanizmu uwierzytelnienia w agencie RSA. Atakujący zdalny, nieuwierzytelniony użytkownik może potencjalnie ominąć proces weryfikacji tożsamości bez konieczności posiadania prawidłowych danych logowania. Wektor ataku sieciowy (AV:N) bez wymagań dotyczących uprawnień (PR:N) ani interakcji użytkownika (UI:N) oznacza, że exploit może być przeprowadzony bezpośrednio przez sieć.
Atakujący może uzyskać nieautoryzowany dostęp do zasobów chronionych przez RSA Authentication Agent, omijając mechanizmy uwierzytelnienia wieloskładnikowego. Skutkuje to pełnym naruszeniem poufności, integralności i dostępności chronionych systemów (C:H/I:H/A:H).
Należy zaktualizować RSA Authentication Agent for Web: Apache Web Server do wersji 8.0.1 build 618 lub nowszej. Szczegółowe instrukcje dostępne są w referencjach producenta oraz biuletynie bezpieczeństwa opublikowanym na liście Full Disclosure.
EMC RSA Authentication Agent for Web: Apache Web Server w wersji 8.0 oraz wersji 8.0.1 przed build 618
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRsa Authentication Agent For Web
APPRsa8.08.0.1
Powiązane podatności
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by ...
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access contr...
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by ...
Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to...
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5...