
====================================================================

                             CERT-Renater

                  Note d'Information No. 2012/VULN407
____________________________________________________________________

DATE                : 11/10/2012

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S) : Systems RSA Adaptive Authentication (On-Premise)
                             version 6.0.2.1.

======================================================================
http://www.securityfocus.com/archive/1/524344/30/0/threaded
______________________________________________________________________

ESA-2012-035: RSA Adaptive Authentication (On-Premise) Information
Disclosure Vulnerability

EMC Identifier: ESA-2012-035

CVE Identifier: CVE-2012-2286

Severity Rating: CVSS v2 Base Score: 7.9 (AV:A/AC:M/Au:N/C:C/I:C/A:C)

Affected Products:

RSA Adaptive Authentication (On-Premise) 6.0.2.1


Summary:

RSA Adaptive Authentication (On-Premise) contains a vulnerability that
can potentially lead to sensitive information disclosure.


Details:

RSA Adaptive Authentication (On-Premise) contains a vulnerability that
could allow sensitive information disclosure when calling specific
components within the application.


Recommendation:

RSA AAOP (On-Premise) 6.0.2.1 SP3 P3 contains changes that resolve this
issue.
See the Release Notes for the required configuration changes to enable
the fix in your environment.


Severity Rating:

For an explanation of Severity Ratings, refer to the Knowledge Base
Article, "Security Advisories Severity Rating" at
https://knowledge.rsasecurity.com/scolcms/knowledge.aspx?solution=a46604.
RSA recommends all customers take into account both the base score and
any relevant temporal and environmental scores which may impact the
potential severity associated with particular security vulnerability.



Obtaining Downloads:

To obtain the latest RSA product downloads, log on to RSA SecurCare
Online at
https://knowledge.rsasecurity.com and click Products in the top
navigation menu. Select the specific product whose download you want to
obtain. Scroll to the section for the product download that you want
and click on the link.


Obtaining Documentation:

To obtain RSA documentation, log on to RSA SecurCare Online at
https://knowledge.rsasecurity.com and click Products in the top
navigation menu. Select the specific product whose documentation you
want to obtain.
Scroll to the section for the product version that you want and click
the set link.


Obtaining More Information:

For more information about RSA Adaptive Authentication, visit the RSA
web site at http://www.rsa.com/node.aspx?id=3018.


Getting Support and Service:

For customers with current maintenance contracts, contact your local
RSA Customer Support center with any additional questions regarding
this RSA SecurCare Note. For contact telephone numbers or e-mail
addresses, log on to RSA SecurCare Online at
https://knowledge.rsasecurity.com, click Help &
Contact, and then click the Contact Us - Phone tab or the Contact Us -
Email tab.


General Customer Support Information:

http://www.rsa.com/node.aspx?id=1264


RSA SecurCare Online:

https://knowledge.rsasecurity.com


EOPS Policy:

RSA has a defined End of Primary Support policy associated with all
major versions. Please refer to the link below for additional details.
http://www.rsa.com/node.aspx?id=2575



SecurCare Online Security Advisories

RSA, The Security Division of EMC, distributes SCOL Security Advisories
in order to bring to the attention of users of the affected RSA
products important security information. RSA recommends that all users
determine the applicability of this information to their individual
situations and take appropriate action.
The information set forth herein is provided "as is" without warranty
of any kind. RSA disclaim all warranties, either express or implied,
including the warranties of merchantability, fitness for a particular
purpose, title and non-infringement. In no event shall RSA or its
suppliers be liable for any damages whatsoever including direct,
indirect, incidental, consequential, loss of business profits or
special damages, even if RSA or its suppliers have been
advised of the possibility of such damages. Some states do not allow
the exclusion or limitation of liability for consequential or
incidental damages so the foregoing limitation may not apply.


About RSA SecurCare Notes & Security Advisories Subscription

RSA SecurCare Notes & Security Advisories are targeted e-mail messages
that RSA sends you based on the RSA product family you currently use.
If you'd like to stop receiving RSA SecurCare Notes & Security
Advisories, or if you'd like to change which RSA product family Notes &
Security Advisories you currently receive, log on to RSA SecurCare
Online at
https://knowledge.rsasecurity.com/scolcms/help.aspx?_v=view3. Following
the instructions on the page, remove the check mark next to the RSA
product family whose Notes & Security Advisories you no longer want to
receive. Click the Submit button to save your selection.


EMC Product Security Response Center

Security_Alert@emc.com

http://www.emc.com/contact-us/contact/product-security-response-center.html

======================================================================

=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
=========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44          +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
+ 75013 Paris           | email: certsvp@renater.fr     +
=========================================================
