Description

RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.

INFO

Published Date :

2025-02-17T00:00:00.000Z

Last Modified :

2025-02-18T16:05:07.133Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-25066 vulnerability.

Vendors Products
Rsa
  • Authentication Manager

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact