RSA maintains a focused portfolio of enterprise identity, governance, and risk-management products—principally its Archer platform, Authentication Manager, and Envision suite—that serve as critical infrastructure in large organizations' access-control and compliance workflows. Despite the narrow product range, this vendor ranks among the most prominent in the vulnerability landscape, reflecting the high value and broad deployment of its governance and authentication solutions. The vulnerability exposure recurs through application-layer weakness classes including cross-site scripting, authentication bypass, and sensitive-information disclosure, which are characteristic of web-facing identity and governance platforms. A moderate share of disclosures acquire public exploit availability, reflecting the appeal of identity systems as high-value attack targets. Defenders should treat RSA product advisories as priority items given their role in access-control enforcement; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rsa over time
Signals from CVEs in this vendor scope (115 CVEs).
115 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4734MEDIUM Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code v | Dec 31, 2005 | 6.4 | 64 | NO | YES |
CVE-2018-1247HIGH RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial | May 8, 2018 | 7.1 | 41 | NO | YES |
CVE-1999-0834HIGH Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library. | Dec 1, 1999 | 10.0 | 35 | NO | YES |
CVE-2024-47856CRITICAL In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotat | Nov 24, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-47529MEDIUM Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service con | Mar 28, 2023 | 6.7 | 32 | NO | YES |
CVE-2007-2417HIGH Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/ | Jul 15, 2007 | 10.0 | 32 | NO | NO |
CVE-2017-14377CRITICAL EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnera | Nov 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2019-3758CRITICAL RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient crede | Sep 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-3725CRITICAL RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input va | May 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-30584HIGH Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to | May 26, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (115 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rsa.
Media articles that mention a CVE ID that affects a product developed by Rsa — matched by CVE ID, not by vendor name.