JSCI SSO URI Pattern Matching Access Validation Vulnerability
BID:8353
Info
JSCI SSO URI Pattern Matching Access Validation Vulnerability
| Bugtraq ID: | 8353 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2003 12:00AM |
| Updated: | Aug 06 2003 12:00AM |
| Credit: | This vulnerability has been disclosed by the vendor in a security announcement. |
| Vulnerable: |
Wedgetail Communications JCSI SSO suite 1.1 |
| Not Vulnerable: |
Wedgetail Communications JCSI SSO suite 1.2 Wedgetail Communications JCSI SSO suite 1.0.2 Wedgetail Communications JCSI SSO suite 1.0 |
Discussion
JSCI SSO URI Pattern Matching Access Validation Vulnerability
JSCI SSO has been reported prone to an access validation vulnerability under certain circumstances.
The issue presents itself in pattern-matching tags contained in JSCI SSO configuration files; these tags are used when controlling access to Java applications. It has been reported that these pattern-matching tags match an entire URI rather than the relative path to the secured Java application. This may mean that if the protected Java application is moved and has a different context root, JSCI SSO will not protect it.
JSCI SSO has been reported prone to an access validation vulnerability under certain circumstances.
The issue presents itself in pattern-matching tags contained in JSCI SSO configuration files; these tags are used when controlling access to Java applications. It has been reported that these pattern-matching tags match an entire URI rather than the relative path to the secured Java application. This may mean that if the protected Java application is moved and has a different context root, JSCI SSO will not protect it.
Exploit / POC
JSCI SSO URI Pattern Matching Access Validation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
JSCI SSO URI Pattern Matching Access Validation Vulnerability
Solution:
The vendor has reported that a fix for this vulnerability will be available in JCSI SSO version 1.2.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has reported that a fix for this vulnerability will be available in JCSI SSO version 1.2.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
JSCI SSO URI Pattern Matching Access Validation Vulnerability
References:
References:
- JCSI SSO Suite Homepage (Wedgetail Communications)