Back to Database
Status published
Medium
CVE-2024-25066
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML...
Vulnerability Description
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25066
Credits & Attribution
No credits recorded in the NVD database.
References
More from RSA
View All →CVE-2019-3725
Command Injection vulnerability
Critical
9.8
CVE-2019-3724
Authorization Bypass VulnerabilityRSA Netwitness Platform
Medium
6.5
CVE-2018-1255
Reflected Cross-Site Scripting Vulnerability
Medium
6.1
CVE-2018-1254
RSA Authentication Manager Security Console, versions 8.3 P1 and earlier,...
Medium
6.1
CVE-2018-1253
Stored cross-site scripting vulnerability
Medium
6.5
Affected Vendor
Affected Software
Authentication Manager
Vulnerable Versions:
0
Timeline
Official Publish:
February 17th, 2025
Last Modified:
February 18th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N