RSA records
116 published records for vendor rsa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')4
- CWE-287 Improper Authentication4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-20 Improper Input Validation3
The weakness classes this vendor ships most often: where to look.
CWEAll records
116 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2007-2417No exploit | Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager rsa · securid | Critical10.0 | — | 16.2% | Jul 15, 2007 |
42Plan | CVE-2005-4734Weaponized | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remorsa · authentication agent for web | Medium6.4 | — | 55.3% | Dec 31, 2005 |
41Plan | CVE-1999-0834Proof of concept | Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.rsa · rsaref | Critical10.0 | — | 2.1% | Dec 1, 1999 |
40Plan | CVE-2017-14377No exploit | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prrsa · authentication agent for web · CWE-287 | Critical9.8 | — | 3.0% | Nov 29, 2017 |
40Plan | CVE-2019-3725No exploit | Command Injection vulnerabilityrsa · netwitness · CWE-78 | Critical9.8 | — | 2.8% | May 15, 2019 |
39Monitor | CVE-2019-3758No exploit | RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.rsa · archer · CWE-288 | Critical9.8 | — | 1.5% | Sep 18, 2019 |
39Monitor | CVE-2024-47856No exploit | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or morrsa · authentication agent for windows · CWE-23 | Critical9.8 | — | 0.5% | Nov 24, 2025 |
38Monitor | CVE-2012-0402No exploit | EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access rsa · envision · CWE-255 | Critical9.3 | — | 2.1% | Mar 20, 2012 |
37Monitor | CVE-2011-4141No exploit | Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horsa · securid | Critical9.3 | — | 1.7% | Dec 16, 2011 |
36Monitor | CVE-2018-11060No exploit | RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.rsa · archer | High8.8 | — | 3.0% | Jul 24, 2018 |
36Monitor | CVE-2014-4627No exploit | SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL corsa · web threat detection · CWE-89 | High8.8 | — | 2.3% | Nov 7, 2014 |
36Monitor | CVE-2018-1252No exploit | RSA Web Threat Detection SQL Injection Vulnerabilityrsa · web threat detection · CWE-89 | High8.8 | — | 2.0% | Jun 5, 2018 |
35Monitor | CVE-2019-3724No exploit | Authorization Bypass VulnerabilityRSA Netwitness Platformrsa · netwitness platform | High8.8 | — | 1.6% | May 15, 2019 |
35Monitor | CVE-2022-30584No exploit | Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentrsa · archer | High8.8 | — | 1.0% | May 26, 2022 |
35Monitor | CVE-2020-5335No exploit | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.rsa · archer · CWE-352 | High8.8 | — | 0.5% | May 4, 2020 |
33Monitor | CVE-2018-1247Proof of concept | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.rsa · authentication manager · CWE-611 | High7.1 | — | 16.0% | May 8, 2018 |
33Monitor | CVE-2020-5384No exploit | Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.rsa · multifactor authentication agent · CWE-288 | High8.4 | — | 0.4% | Jul 31, 2020 |
31Monitor | CVE-2012-0397No exploit | Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly exrsa · securid software token converter · CWE-119 | High7.6 | — | 2.7% | Mar 6, 2012 |
31Monitor | CVE-2018-1232No exploit | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow rsa · authentication agent for web · CWE-787 | High7.5 | — | 2.7% | Mar 30, 2018 |
31Monitor | CVE-2005-1471No exploit | Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-enrsa · securid web agent | High7.5 | — | 2.6% | May 6, 2005 |
31Monitor | CVE-2001-1461No exploit | Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows rsa · securid | High7.5 | — | 1.8% | Oct 22, 2001 |
31Monitor | CVE-2012-0400No exploit | EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for rrsa · envision · CWE-287 | High7.9 | — | 1.3% | Mar 20, 2012 |
31Monitor | CVE-2018-15782No exploit | DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerabilityrsa · authentication manager · CWE-22 | High7.8 | — | 0.4% | Jan 16, 2019 |
31Monitor | CVE-2018-1182No exploit | An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwaremc · rsa identity governance and lifecycle · CWE-269 | High7.8 | — | 0.4% | Mar 8, 2018 |
31Monitor | CVE-2019-3716No exploit | Information Exposure Vulnerabilityrsa · archer grc platform · CWE-532 | High7.8 | — | 0.4% | Mar 13, 2019 |
- CVE-2007-241745Plan
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager
CriticalCVSS 10.0No exploitEPSS 16%rsa · securidJul 15, 2007
- CVE-2005-473442Plan
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remo
MediumCVSS 6.4WeaponizedEPSS 55%rsa · authentication agent for webDec 31, 2005
- CVE-1999-083441Plan
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
CriticalCVSS 10.0Proof of conceptEPSS 2%rsa · rsarefDec 1, 1999
- CVE-2017-1437740Plan
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 pr
CriticalCVSS 9.8No exploitEPSS 3%rsa · authentication agent for webNov 29, 2017
- CVE-2019-372540Plan
Command Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 3%rsa · netwitnessMay 15, 2019
- CVE-2019-375839Monitor
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%rsa · archerSep 18, 2019
- CVE-2024-4785639Monitor
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or mor
CriticalCVSS 9.8No exploitEPSS 1%rsa · authentication agent for windowsNov 24, 2025
- CVE-2012-040238Monitor
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access
CriticalCVSS 9.3No exploitEPSS 2%rsa · envisionMar 20, 2012
- CVE-2011-414137Monitor
Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan ho
CriticalCVSS 9.3No exploitEPSS 2%rsa · securidDec 16, 2011
- CVE-2018-1106036Monitor
RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.
HighCVSS 8.8No exploitEPSS 3%rsa · archerJul 24, 2018
- CVE-2014-462736Monitor
SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL co
HighCVSS 8.8No exploitEPSS 2%rsa · web threat detectionNov 7, 2014
- CVE-2018-125236Monitor
RSA Web Threat Detection SQL Injection Vulnerability
HighCVSS 8.8No exploitEPSS 2%rsa · web threat detectionJun 5, 2018
- CVE-2019-372435Monitor
Authorization Bypass VulnerabilityRSA Netwitness Platform
HighCVSS 8.8No exploitEPSS 2%rsa · netwitness platformMay 15, 2019
- CVE-2022-3058435Monitor
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potent
HighCVSS 8.8No exploitEPSS 1%rsa · archerMay 26, 2022
- CVE-2020-533535Monitor
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.
HighCVSS 8.8No exploitEPSS 0%rsa · archerMay 4, 2020
- CVE-2018-124733Monitor
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.
HighCVSS 7.1Proof of conceptEPSS 16%rsa · authentication managerMay 8, 2018
- CVE-2020-538433Monitor
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.
HighCVSS 8.4No exploitEPSS 0%rsa · multifactor authentication agentJul 31, 2020
- CVE-2012-039731Monitor
Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly ex
HighCVSS 7.6No exploitEPSS 3%rsa · securid software token converterMar 6, 2012
- CVE-2018-123231Monitor
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow
HighCVSS 7.5No exploitEPSS 3%rsa · authentication agent for webMar 30, 2018
- CVE-2005-147131Monitor
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-en
HighCVSS 7.5No exploitEPSS 3%rsa · securid web agentMay 6, 2005
- CVE-2001-146131Monitor
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows
HighCVSS 7.5No exploitEPSS 2%rsa · securidOct 22, 2001
- CVE-2012-040031Monitor
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for r
HighCVSS 7.9No exploitEPSS 1%rsa · envisionMar 20, 2012
- CVE-2018-1578231Monitor
DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerability
HighCVSS 7.8No exploitEPSS 0%rsa · authentication managerJan 16, 2019
- CVE-2018-118231Monitor
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwar
HighCVSS 7.8No exploitEPSS 0%emc · rsa identity governance and lifecycleMar 8, 2018
- CVE-2019-371631Monitor
Information Exposure Vulnerability
HighCVSS 7.8No exploitEPSS 0%rsa · archer grc platformMar 13, 2019