Skip to main content

RSA Access Manager Session Replay Vulnerability

Last Update Date: 5 Jul 2012 10:14 Release Date: 5 Jul 2012 4987 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in RSA Access Manager. A remote user can exploit a flaw in the logout process and replay session credentials to gain access to the target system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Server version 6.0.x, 6.1, 6.1 SP1, 6.1 SP2, 6.1 SP3
  • All Agent versions

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.
    For 6.1 SP4: hot fix # AxM HF 6.0.4.64
    For Server version 6.0.4: hot fix # AxM HF 6.0.4.64
    For Server version 6.1 SP3: hot fix # AxM HF 6.1.3.30

Vulnerability Identifier


Source


Related Link