Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
BID:58609
Info
Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
| Bugtraq ID: | 58609 |
| Class: | Design Error |
| CVE: |
CVE-2013-2279 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2013 12:00AM |
| Updated: | Mar 19 2013 12:00AM |
| Credit: | Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann, and Meiko Jensen. |
| Vulnerable: |
Computer Associates SiteMinder for Secure Proxy Server 6.0 Computer Associates SiteMinder for Secure Proxy Server 12.5 Computer Associates SiteMinder for Secure Proxy Server 12.0 Computer Associates SiteMinder Federation(Standalone) 12.1 Computer Associates SiteMinder Federation(Standalone) 12.0 Computer Associates SiteMinder Federation(FSS) 12.5 Computer Associates SiteMinder Federation(FSS) 12.0 Computer Associates SiteMinder Federation r6 Computer Associates SiteMinder Agent for SharePoint 2010 0 |
| Not Vulnerable: |
Computer Associates SiteMinder for Secure Proxy Server 12.5 CR2 Computer Associates SiteMinder Federation(Standalone) 12.5 Computer Associates SiteMinder Federation(FSS) 12.5 CR2 Computer Associates SiteMinder Federation(FSS) 12.0 SP3 CR12 Computer Associates SiteMinder Federation r6 SP6 CR10 Computer Associates SiteMinder Agent for SharePoint 2010 12.5.1 |
Discussion
Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
Multiple CA SiteMinder products are prone to a signature-verification security-bypass vulnerability.
An attacker can exploit this issue to bypass the signature validation mechanism and impersonate another user.
This vulnerability affects the following products:
CA SiteMinder Federation
CA SiteMinder Agent for SharePoint
CA SiteMinder for Secure Proxy Server
Multiple CA SiteMinder products are prone to a signature-verification security-bypass vulnerability.
An attacker can exploit this issue to bypass the signature validation mechanism and impersonate another user.
This vulnerability affects the following products:
CA SiteMinder Federation
CA SiteMinder Agent for SharePoint
CA SiteMinder for Secure Proxy Server
Exploit / POC
Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple CA SiteMinder Products SAML Signature Validation Security Bypass Vulnerability
References:
References: