VU#273940: Enterprise Access Management EAM does not rotate RSA keys

CERT Coordination Center Version 2 imported change current

Imported from official source

Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. …

This version

Version
2 of 2
Recorded
September 24, 2026 20:00
Change
Imported change
Content hash
6aaa32ec26b346670413feeb750f760b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.