Записи RSA
116 опубликованных записей вендора rsa.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,9 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')4
- CWE-287 Improper Authentication4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-20 Improper Input Validation3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
116 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2007-2417Эксплойта нет | Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager rsa · securid | Критическая10,0 | — | 16,2 % | 15 июл. 2007 г. |
42В плане | CVE-2005-4734Готовый эксплойт | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remorsa · authentication agent for web | Средняя6,4 | — | 55,3 % | 31 дек. 2005 г. |
41В плане | CVE-1999-0834Proof of concept | Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.rsa · rsaref | Критическая10,0 | — | 2,1 % | 1 дек. 1999 г. |
40В плане | CVE-2017-14377Эксплойта нет | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prrsa · authentication agent for web · CWE-287 | Критическая9,8 | — | 3,0 % | 29 нояб. 2017 г. |
40В плане | CVE-2019-3725Эксплойта нет | Command Injection vulnerabilityrsa · netwitness · CWE-78 | Критическая9,8 | — | 2,8 % | 15 мая 2019 г. |
39Наблюдать | CVE-2019-3758Эксплойта нет | RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.rsa · archer · CWE-288 | Критическая9,8 | — | 1,5 % | 18 сент. 2019 г. |
39Наблюдать | CVE-2024-47856Эксплойта нет | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or morrsa · authentication agent for windows · CWE-23 | Критическая9,8 | — | 0,5 % | 24 нояб. 2025 г. |
38Наблюдать | CVE-2012-0402Эксплойта нет | EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access rsa · envision · CWE-255 | Критическая9,3 | — | 2,1 % | 20 мар. 2012 г. |
37Наблюдать | CVE-2011-4141Эксплойта нет | Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horsa · securid | Критическая9,3 | — | 1,7 % | 16 дек. 2011 г. |
36Наблюдать | CVE-2018-11060Эксплойта нет | RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.rsa · archer | Высокая8,8 | — | 3,0 % | 24 июл. 2018 г. |
36Наблюдать | CVE-2014-4627Эксплойта нет | SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL corsa · web threat detection · CWE-89 | Высокая8,8 | — | 2,3 % | 7 нояб. 2014 г. |
36Наблюдать | CVE-2018-1252Эксплойта нет | RSA Web Threat Detection SQL Injection Vulnerabilityrsa · web threat detection · CWE-89 | Высокая8,8 | — | 2,0 % | 5 июн. 2018 г. |
35Наблюдать | CVE-2019-3724Эксплойта нет | Authorization Bypass VulnerabilityRSA Netwitness Platformrsa · netwitness platform | Высокая8,8 | — | 1,6 % | 15 мая 2019 г. |
35Наблюдать | CVE-2022-30584Эксплойта нет | Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentrsa · archer | Высокая8,8 | — | 1,0 % | 26 мая 2022 г. |
35Наблюдать | CVE-2020-5335Эксплойта нет | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.rsa · archer · CWE-352 | Высокая8,8 | — | 0,5 % | 4 мая 2020 г. |
33Наблюдать | CVE-2018-1247Proof of concept | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.rsa · authentication manager · CWE-611 | Высокая7,1 | — | 16,0 % | 8 мая 2018 г. |
33Наблюдать | CVE-2020-5384Эксплойта нет | Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.rsa · multifactor authentication agent · CWE-288 | Высокая8,4 | — | 0,4 % | 31 июл. 2020 г. |
31Наблюдать | CVE-2012-0397Эксплойта нет | Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly exrsa · securid software token converter · CWE-119 | Высокая7,6 | — | 2,7 % | 6 мар. 2012 г. |
31Наблюдать | CVE-2018-1232Эксплойта нет | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow rsa · authentication agent for web · CWE-787 | Высокая7,5 | — | 2,7 % | 30 мар. 2018 г. |
31Наблюдать | CVE-2005-1471Эксплойта нет | Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-enrsa · securid web agent | Высокая7,5 | — | 2,6 % | 6 мая 2005 г. |
31Наблюдать | CVE-2001-1461Эксплойта нет | Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows rsa · securid | Высокая7,5 | — | 1,8 % | 22 окт. 2001 г. |
31Наблюдать | CVE-2012-0400Эксплойта нет | EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for rrsa · envision · CWE-287 | Высокая7,9 | — | 1,3 % | 20 мар. 2012 г. |
31Наблюдать | CVE-2018-15782Эксплойта нет | DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerabilityrsa · authentication manager · CWE-22 | Высокая7,8 | — | 0,4 % | 16 янв. 2019 г. |
31Наблюдать | CVE-2018-1182Эксплойта нет | An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwaremc · rsa identity governance and lifecycle · CWE-269 | Высокая7,8 | — | 0,4 % | 8 мар. 2018 г. |
31Наблюдать | CVE-2019-3716Эксплойта нет | Information Exposure Vulnerabilityrsa · archer grc platform · CWE-532 | Высокая7,8 | — | 0,4 % | 13 мар. 2019 г. |
- CVE-2007-241745В плане
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager
КритическаяCVSS 10,0Эксплойта нетEPSS 16 %rsa · securid15 июл. 2007 г.
- CVE-2005-473442В плане
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remo
СредняяCVSS 6,4Готовый эксплойтEPSS 55 %rsa · authentication agent for web31 дек. 2005 г.
- CVE-1999-083441В плане
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
КритическаяCVSS 10,0Proof of conceptEPSS 2 %rsa · rsaref1 дек. 1999 г.
- CVE-2017-1437740В плане
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 pr
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rsa · authentication agent for web29 нояб. 2017 г.
- CVE-2019-372540В плане
Command Injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rsa · netwitness15 мая 2019 г.
- CVE-2019-375839Наблюдать
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rsa · archer18 сент. 2019 г.
- CVE-2024-4785639Наблюдать
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or mor
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rsa · authentication agent for windows24 нояб. 2025 г.
- CVE-2012-040238Наблюдать
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %rsa · envision20 мар. 2012 г.
- CVE-2011-414137Наблюдать
Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan ho
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %rsa · securid16 дек. 2011 г.
- CVE-2018-1106036Наблюдать
RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %rsa · archer24 июл. 2018 г.
- CVE-2014-462736Наблюдать
SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL co
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %rsa · web threat detection7 нояб. 2014 г.
- CVE-2018-125236Наблюдать
RSA Web Threat Detection SQL Injection Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %rsa · web threat detection5 июн. 2018 г.
- CVE-2019-372435Наблюдать
Authorization Bypass VulnerabilityRSA Netwitness Platform
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %rsa · netwitness platform15 мая 2019 г.
- CVE-2022-3058435Наблюдать
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potent
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rsa · archer26 мая 2022 г.
- CVE-2020-533535Наблюдать
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %rsa · archer4 мая 2020 г.
- CVE-2018-124733Наблюдать
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.
ВысокаяCVSS 7,1Proof of conceptEPSS 16 %rsa · authentication manager8 мая 2018 г.
- CVE-2020-538433Наблюдать
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %rsa · multifactor authentication agent31 июл. 2020 г.
- CVE-2012-039731Наблюдать
Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly ex
ВысокаяCVSS 7,6Эксплойта нетEPSS 3 %rsa · securid software token converter6 мар. 2012 г.
- CVE-2018-123231Наблюдать
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rsa · authentication agent for web30 мар. 2018 г.
- CVE-2005-147131Наблюдать
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-en
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rsa · securid web agent6 мая 2005 г.
- CVE-2001-146131Наблюдать
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rsa · securid22 окт. 2001 г.
- CVE-2012-040031Наблюдать
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for r
ВысокаяCVSS 7,9Эксплойта нетEPSS 1 %rsa · envision20 мар. 2012 г.
- CVE-2018-1578231Наблюдать
DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %rsa · authentication manager16 янв. 2019 г.
- CVE-2018-118231Наблюдать
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwar
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %emc · rsa identity governance and lifecycle8 мар. 2018 г.
- CVE-2019-371631Наблюдать
Information Exposure Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %rsa · archer grc platform13 мар. 2019 г.