When the user enters an incorrect password, the old version SA( Strong Authentication) 9.1 web method verifyPassword() returns an http 500 response to the client application.
In Strong Authentication 9.1.5.1, the client application receives the http code 400.
Release : Symantec Strong Authentication 9.1.5.1
OS : Windows
Our recommendation is to apply the patch Symantec-AdvAuth-9.1.5.1-DE637008-HotFix to resolve this issue. The patch can be downloaded from the KB article as well.