EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might allow remote attackers to conduct replay attacks via unspecified vectors.
2012-07-05T14:55:02.247
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:A/AC:H/Au:N/C:C/I:C/A:C
3.2
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rsa | access_manager_agent | * | Yes |
Application | rsa | access_manager_server | 6.0 | Yes |
Application | rsa | access_manager_server | 6.1 | Yes |
Application | rsa | access_manager_server | 6.1 | Yes |
Application | rsa | access_manager_server | 6.1 | Yes |
Application | rsa | access_manager_server | 6.1 | Yes |