Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1753376-3)
SAP Support Packages
(SECURITY_EXTENSIONS_720_SP003_000003, SECURITY_EXTENSIONS_720_SP004_000002, SECURITY_EXTENSIONS_720_SP005_000002, SECURITY_EXTENSIONS_720_SP006_000001, SECURITY_EXTENSIONS_720_SP007_000001, SECURITY_EXTENSIONS_720_SP008_000000, SECURITY_EXTENSIONS_720_SP009_000000, SECURITY_EXTENSIONS_720_SP999999_999999, SECURITY_EXTENSIONS_730_SP001_000002, SECURITY_EXTENSIONS_730_SP002_000002, SECURITY_EXTENSIONS_730_SP003_000003, SECURITY_EXTENSIONS_730_SP004_000002, SECURITY_EXTENSIONS_730_SP005_000002, SECURITY_EXTENSIONS_730_SP007_000004, SECURITY_EXTENSIONS_730_SP008_000000, SECURITY_EXTENSIONS_730_SP009_000000, SECURITY_EXTENSIONS_730_SP999999_999999, SECURITY_EXTENSIONS_731_SP001_000001, SECURITY_EXTENSIONS_731_SP002_000001, SECURITY_EXTENSIONS_731_SP003_000001, SECURITY_EXTENSIONS_731_SP004_000001, SECURITY_EXTENSIONS_731_SP005_000000, SECURITY_EXTENSIONS_731_SP006_000000, SECURITY_EXTENSIONS_731_SP999999_999999)
Описание
The SAML 2.0 Service Provider implementation contains a vulnerability in the manner in which XML signatures are used to certify security assertions. This issue affects multiple vendors of SAML 2.0 implementations, and is not SAP specific. A malicious user can intercept or issue one signed assertion, and use an XML signature wrapping attack to gain higher privileges or impersonate another user. This means that there is a risk of information disclosure, data tampering and system unavailability as a result of this vulnerability.
Как исправить
Apply the patches in the note according to the used version and Service Pack level.
Ссылки