IBM Client Security Password Manager Design Error Vulnerability
BID:20308
Info
IBM Client Security Password Manager Design Error Vulnerability
| Bugtraq ID: | 20308 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2006 12:00AM |
| Updated: | Oct 04 2006 08:25PM |
| Credit: | Discovery of this vulnerability is credited to Luis Miguel Silva. |
| Vulnerable: |
IBM Client Security Password Manager 0 |
| Not Vulnerable: | |
Discussion
IBM Client Security Password Manager Design Error Vulnerability
IBM Client Security Password Manager is prone to a design error that degrades the integrity of client-side web security.
The vulnerability stems from the fact that the Password Manager relies on 'Window Title' information as part of the authentication routine it performs on behalf of the user. A malicious website can establish a web page that spoofs the same window title that the application expects to map. This will allow authentication to proceed with the hostile site and in turn establish a false sense of security on the part of visitors who use the affected software.
Exploiting this issue can help attackers steal user credentials. Other attacks are also possible.
IBM Client Security Password Manager version 1.40.10.0 is confirmed vulnerable; other versions may be affected as well.
IBM Client Security Password Manager is prone to a design error that degrades the integrity of client-side web security.
The vulnerability stems from the fact that the Password Manager relies on 'Window Title' information as part of the authentication routine it performs on behalf of the user. A malicious website can establish a web page that spoofs the same window title that the application expects to map. This will allow authentication to proceed with the hostile site and in turn establish a false sense of security on the part of visitors who use the affected software.
Exploiting this issue can help attackers steal user credentials. Other attacks are also possible.
IBM Client Security Password Manager version 1.40.10.0 is confirmed vulnerable; other versions may be affected as well.
Exploit / POC
IBM Client Security Password Manager Design Error Vulnerability
Attackers can exploit this issue via a specially crafted web page.
Attackers can exploit this issue via a specially crafted web page.
Solution / Fix
IBM Client Security Password Manager Design Error Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
IBM Client Security Password Manager Design Error Vulnerability
References:
References:
- IBM Client Security (IBM)
- Vendor Home Page (IBM)
- Security flaw in IBM Client Security Password Manager (Miguel Silva)