RSA products found to have security flaws

RSA has disclosed a number of vulnerabilities affecting its RSA Archer and RSA Authentication Manager products. The flaws could enable an attacker to obtain passwords to use in further attacks.
According to postings on Seclists.org, RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA Archer log files.
"An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks," according to one posting.
There is a second flaw in RSA Archer versions, prior to 6.5 SP2. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks.
Both vulnerabilities have been given CVSSv3 scores of 7.8.
RSA said that it has fixes for the multiple security vulnerabilities that could potentially be exploited by malicious users to compromise the affected system. It recommended that all customers upgrade at the earliest opportunity.
In a second posting, RSA’s Authentication Manager contains a vulnerability associated with insecure credential management.
In versions prior to 8.4 P1, it contains an Insecure Credential Management Vulnerability.
"A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks," RSA said in a statement. The flaw has been given a CVSSv3 Base Score of 5.8.
The company said that organisations should upgrade at the earliest opportunity to RSA Authentication Manager version 8.4 P1 and later.
Marina Kidron, director of threat intelligence at Skybox Lab, Skybox Security, told SC Media UK that initially, organisations need to do an in-depth visibility check that includes up-to-date scans and scan less solutions, and evaluate if they have these products in their network.
"Then apply the patch that’s recommended by the vendor or, if available, apply a network IPS signature. Additionally, you could use multi-factor authentication or and limit users by implementing a Policy of Least Privilege. Both of these approaches would work well here because these vulnerabilities require an authenticated attacker," she said.
"Known vulnerabilities are responsible for 97 percent of breaches and are far more dangerous and far more common than 0-days. The pressure of being in a SIEM arms race can be significantly eased by keeping track of relevant disclosures and patching quickly. Prioritise the patching of security products above that of the hardware and software that sits downstream from them. Vulnerabilities affecting security products are not a new thing, and should be identified, understood and mitigated with respect to the SLA," she added.
source scmagazineuk
Industry: Cyber Security News

Latest Jobs
-
- Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL
- United Kingdom
- N/A
-
Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL Outside IR35 Client facing (Remote UK) with occasional site visit. Must have current Cyber incident response / management experience. Both proactive planning, escalation, coordination and coordinating response. Stakeholder engagement both technical and non technical teams. Prior experience with Technical incident / digital forensics / crisis management. Immediate role.
-
- Tenable Vulnerability Analyst - CONTRACT outside IR35. SC cleared.
- United Kingdom
- N/A
-
6 month rolling contract Outside IR35- immediate start. Threat and Vulnerability Analyst. Tenable.sc experience needed. The ability to deploy agent, configure environments, run active and passive scans, produce reports and prioritise remediation activities based on output Current and ACTIVE SC clearance is required
-
- ForgeRock Consultant
- N/A
- £600 per day
-
ForgeRock Consultant required for 6 Month Contract (with potential to extend) Outside IR35, Must be willing to work Europe hours (GMT+1) This is a remote position, Looking for a lead ForgeRock Technical Consultant with strong experience of ForgeRock to lead the next phase of deployment. Good understanding of ForgeRock Directory Services. · Responsible for the design and implementation of ForgeRock stack · Install and configure ForgeRock stack to meet customer authentication and authorization requirements, · Design and implement OAuth2 protocol using ForgeRock OpenAM, · Design and develop OpenAM custom authentication modules, · Configure ForgeRock stack to protect RESTful API, · Troubleshoot and support ForgeRock IAM stack. · Designed and developed Restful APIs, This is a great project with an expanding ForgeRock Partner, where you will get to work on some high level deployment projects We are looking for someone with the above experience, who is comfortable hitting the ground running and taking on the reins mid project
-
- Network Security Engineer
- Germany
- €550 a day
-
German- based contract opportunity This is an onsite based position, we would need the Network Security engineer to be able to work on the client site 5 days a week Seeking an experienced Network Security Engineer for a leading technology company. Strong expertise in firewall/IPS solutions, proxy solutions, and certificate management is required. Good hands-on experience in networking and web-related technologies necessary. Strong problem-solving skills and the ability to work under pressure are essential. we are looking for a Network Security Engineer with the following experience: · Expertise in Administration, Management & Troubleshooting of Firewall / IPS solutions / Proxy solutions/Certificate Management Solutions · Good Hands-on Experience on security devices (PaloAlto/ /McAfee Proxy/CISCO ISE/Certificate Management) · Good Hands-on Experience in Networking with skills of switching, routing & wireless Technologies · Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocol · Configuration of NAT / PAT, firewall policies, profiling, objects, AD-Integration, backup – restore · Knowledge of Subnetting TCP/IP Communication, VLSM Configuration of VLAN VTP · Configuration of Routing Protocols e.g. RIPv1 & v2, OSPF, EIGRP, BGP Knowledge of standard and extended ACL 12 month contract