XML External Entity Vulnerability in RSA Authentication Manager
CVE-2024-25066
4.3MEDIUM
What is CVE-2024-25066?
The RSA Authentication Manager prior to version 8.7 SP2 Patch 1 is susceptible to XML External Entity (XXE) attacks. This vulnerability allows an attacker to manipulate license files in a way that permits unauthorized access to files on the server hosting the product. Although data exfiltration is not possible, the presence of attacker-controlled files can lead to potential unauthorized information exposure and integrity issues, posing serious risks to the overall security posture of the affected systems.
Affected Version(s)
Authentication Manager 0 < 8.7 SP2 Patch 1