RSA kayıtları
rsa üreticisine ait 116 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,9
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')4
- CWE-287 Improper Authentication4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-20 Improper Input Validation3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
116 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2007-2417İstismar yok | Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager rsa · securid | Kritik10,0 | — | %16,2 | 15 Tem 2007 |
42Planlayın | CVE-2005-4734Silahlaştırılmış | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remorsa · authentication agent for web | Orta6,4 | — | %55,3 | 31 Ara 2005 |
41Planlayın | CVE-1999-0834Kavram kanıtı | Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.rsa · rsaref | Kritik10,0 | — | %2,1 | 1 Ara 1999 |
40Planlayın | CVE-2017-14377İstismar yok | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prrsa · authentication agent for web · CWE-287 | Kritik9,8 | — | %3,0 | 29 Kas 2017 |
40Planlayın | CVE-2019-3725İstismar yok | Command Injection vulnerabilityrsa · netwitness · CWE-78 | Kritik9,8 | — | %2,8 | 15 May 2019 |
39İzleyin | CVE-2019-3758İstismar yok | RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.rsa · archer · CWE-288 | Kritik9,8 | — | %1,5 | 18 Eyl 2019 |
39İzleyin | CVE-2024-47856İstismar yok | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or morrsa · authentication agent for windows · CWE-23 | Kritik9,8 | — | %0,5 | 24 Kas 2025 |
38İzleyin | CVE-2012-0402İstismar yok | EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access rsa · envision · CWE-255 | Kritik9,3 | — | %2,1 | 20 Mar 2012 |
37İzleyin | CVE-2011-4141İstismar yok | Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horsa · securid | Kritik9,3 | — | %1,7 | 16 Ara 2011 |
36İzleyin | CVE-2018-11060İstismar yok | RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.rsa · archer | Yüksek8,8 | — | %3,0 | 24 Tem 2018 |
36İzleyin | CVE-2014-4627İstismar yok | SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL corsa · web threat detection · CWE-89 | Yüksek8,8 | — | %2,3 | 7 Kas 2014 |
36İzleyin | CVE-2018-1252İstismar yok | RSA Web Threat Detection SQL Injection Vulnerabilityrsa · web threat detection · CWE-89 | Yüksek8,8 | — | %2,0 | 5 Haz 2018 |
35İzleyin | CVE-2019-3724İstismar yok | Authorization Bypass VulnerabilityRSA Netwitness Platformrsa · netwitness platform | Yüksek8,8 | — | %1,6 | 15 May 2019 |
35İzleyin | CVE-2022-30584İstismar yok | Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentrsa · archer | Yüksek8,8 | — | %1,0 | 26 May 2022 |
35İzleyin | CVE-2020-5335İstismar yok | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.rsa · archer · CWE-352 | Yüksek8,8 | — | %0,5 | 4 May 2020 |
33İzleyin | CVE-2018-1247Kavram kanıtı | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.rsa · authentication manager · CWE-611 | Yüksek7,1 | — | %16,0 | 8 May 2018 |
33İzleyin | CVE-2020-5384İstismar yok | Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.rsa · multifactor authentication agent · CWE-288 | Yüksek8,4 | — | %0,4 | 31 Tem 2020 |
31İzleyin | CVE-2012-0397İstismar yok | Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly exrsa · securid software token converter · CWE-119 | Yüksek7,6 | — | %2,7 | 6 Mar 2012 |
31İzleyin | CVE-2018-1232İstismar yok | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow rsa · authentication agent for web · CWE-787 | Yüksek7,5 | — | %2,7 | 30 Mar 2018 |
31İzleyin | CVE-2005-1471İstismar yok | Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-enrsa · securid web agent | Yüksek7,5 | — | %2,6 | 6 May 2005 |
31İzleyin | CVE-2001-1461İstismar yok | Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows rsa · securid | Yüksek7,5 | — | %1,8 | 22 Eki 2001 |
31İzleyin | CVE-2012-0400İstismar yok | EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for rrsa · envision · CWE-287 | Yüksek7,9 | — | %1,3 | 20 Mar 2012 |
31İzleyin | CVE-2018-15782İstismar yok | DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerabilityrsa · authentication manager · CWE-22 | Yüksek7,8 | — | %0,4 | 16 Oca 2019 |
31İzleyin | CVE-2018-1182İstismar yok | An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwaremc · rsa identity governance and lifecycle · CWE-269 | Yüksek7,8 | — | %0,4 | 8 Mar 2018 |
31İzleyin | CVE-2019-3716İstismar yok | Information Exposure Vulnerabilityrsa · archer grc platform · CWE-532 | Yüksek7,8 | — | %0,4 | 13 Mar 2019 |
- CVE-2007-241745Planlayın
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager
KritikCVSS 10,0İstismar yokEPSS %16rsa · securid15 Tem 2007
- CVE-2005-473442Planlayın
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remo
OrtaCVSS 6,4SilahlaştırılmışEPSS %55rsa · authentication agent for web31 Ara 2005
- CVE-1999-083441Planlayın
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
KritikCVSS 10,0Kavram kanıtıEPSS %2rsa · rsaref1 Ara 1999
- CVE-2017-1437740Planlayın
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 pr
KritikCVSS 9,8İstismar yokEPSS %3rsa · authentication agent for web29 Kas 2017
- CVE-2019-372540Planlayın
Command Injection vulnerability
KritikCVSS 9,8İstismar yokEPSS %3rsa · netwitness15 May 2019
- CVE-2019-375839İzleyin
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1rsa · archer18 Eyl 2019
- CVE-2024-4785639İzleyin
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or mor
KritikCVSS 9,8İstismar yokEPSS %1rsa · authentication agent for windows24 Kas 2025
- CVE-2012-040238İzleyin
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access
KritikCVSS 9,3İstismar yokEPSS %2rsa · envision20 Mar 2012
- CVE-2011-414137İzleyin
Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan ho
KritikCVSS 9,3İstismar yokEPSS %2rsa · securid16 Ara 2011
- CVE-2018-1106036İzleyin
RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API.
YüksekCVSS 8,8İstismar yokEPSS %3rsa · archer24 Tem 2018
- CVE-2014-462736İzleyin
SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL co
YüksekCVSS 8,8İstismar yokEPSS %2rsa · web threat detection7 Kas 2014
- CVE-2018-125236İzleyin
RSA Web Threat Detection SQL Injection Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2rsa · web threat detection5 Haz 2018
- CVE-2019-372435İzleyin
Authorization Bypass VulnerabilityRSA Netwitness Platform
YüksekCVSS 8,8İstismar yokEPSS %2rsa · netwitness platform15 May 2019
- CVE-2022-3058435İzleyin
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potent
YüksekCVSS 8,8İstismar yokEPSS %1rsa · archer26 May 2022
- CVE-2020-533535İzleyin
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %0rsa · archer4 May 2020
- CVE-2018-124733İzleyin
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability.
YüksekCVSS 7,1Kavram kanıtıEPSS %16rsa · authentication manager8 May 2018
- CVE-2020-538433İzleyin
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability.
YüksekCVSS 8,4İstismar yokEPSS %0rsa · multifactor authentication agent31 Tem 2020
- CVE-2012-039731İzleyin
Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly ex
YüksekCVSS 7,6İstismar yokEPSS %3rsa · securid software token converter6 Mar 2012
- CVE-2018-123231İzleyin
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow
YüksekCVSS 7,5İstismar yokEPSS %3rsa · authentication agent for web30 Mar 2018
- CVE-2005-147131İzleyin
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-en
YüksekCVSS 7,5İstismar yokEPSS %3rsa · securid web agent6 May 2005
- CVE-2001-146131İzleyin
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows
YüksekCVSS 7,5İstismar yokEPSS %2rsa · securid22 Eki 2001
- CVE-2012-040031İzleyin
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for r
YüksekCVSS 7,9İstismar yokEPSS %1rsa · envision20 Mar 2012
- CVE-2018-1578231İzleyin
DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0rsa · authentication manager16 Oca 2019
- CVE-2018-118231İzleyin
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and softwar
YüksekCVSS 7,8İstismar yokEPSS %0emc · rsa identity governance and lifecycle8 Mar 2018
- CVE-2019-371631İzleyin
Information Exposure Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0rsa · archer grc platform13 Mar 2019