CVE-2024-25066

RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) RSA Authentication Manager anterior a la versión 8.7 SP2 Patch 1 permite ataques de entidad externa XML (XXE) a través de un archivo de licencia, lo que hace que los archivos controlados por el atacante se almacenen en el servidor del producto. No se puede producir la exfiltración de datos.

17 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-17 21:15

Updated : 2026-06-17 07:15


NVD link : CVE-2024-25066

Mitre link : CVE-2024-25066

CVE.ORG link : CVE-2024-25066


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference