First published: Mon Feb 17 2025(Updated: )
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Manager | <8.7 SP2 Patch 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25066 has a medium severity rating due to the potential for XML External Entity (XXE) attacks.
To remediate CVE-2024-25066, upgrade to RSA Authentication Manager version 8.7 SP2 Patch 1 or later.
The consequence of CVE-2024-25066 is that attacker-controlled files may be stored on the server, impacting data integrity.
No, data exfiltration cannot occur as a result of CVE-2024-25066.
RSA Authentication Manager versions prior to 8.7 SP2 Patch 1 are affected by CVE-2024-25066.