Release date:
Updated on:
Affected Systems:
RSA Security Access Manager Server 6.x
RSA Security Access Manager Agent 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54301
Cve id: CVE-2012-2281
RSA is a security, compliance, and risk management solution. RSA Access Manager provides Secure Access Management and Access control for Web applications from a single console.
All supported versions of RSA Access Manager 6.1 SP4 6.0.x, 6.1, and RSA Access Manager Agent after the user exits, there is an error in verifying the session token, which can be used to replay the session.
<* Source: vendor
Link: http://secunia.com/advisories/49757/
Http://archives.neohapsis.com/archives/bugtraq/2012-07/0037.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RSA Security
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rsasecurity.com