• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1753376 - SAML 2.0: possible XML Signature wrapping attack

Главная Специалистам База уязвимостей Note 1753376 - SAML 2.0: possible XML Signature wrapping attack

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1753376-3) SAP Support Packages (SECURITY_EXTENSIONS_720_SP003_000003, SECURITY_EXTENSIONS_720_SP004_000002, SECURITY_EXTENSIONS_720_SP005_000002, SECURITY_EXTENSIONS_720_SP006_000001, SECURITY_EXTENSIONS_720_SP007_000001, SECURITY_EXTENSIONS_720_SP008_000000, SECURITY_EXTENSIONS_720_SP009_000000, SECURITY_EXTENSIONS_720_SP999999_999999, SECURITY_EXTENSIONS_730_SP001_000002, SECURITY_EXTENSIONS_730_SP002_000002, SECURITY_EXTENSIONS_730_SP003_000003, SECURITY_EXTENSIONS_730_SP004_000002, SECURITY_EXTENSIONS_730_SP005_000002, SECURITY_EXTENSIONS_730_SP007_000004, SECURITY_EXTENSIONS_730_SP008_000000, SECURITY_EXTENSIONS_730_SP009_000000, SECURITY_EXTENSIONS_730_SP999999_999999, SECURITY_EXTENSIONS_731_SP001_000001, SECURITY_EXTENSIONS_731_SP002_000001, SECURITY_EXTENSIONS_731_SP003_000001, SECURITY_EXTENSIONS_731_SP004_000001, SECURITY_EXTENSIONS_731_SP005_000000, SECURITY_EXTENSIONS_731_SP006_000000, SECURITY_EXTENSIONS_731_SP999999_999999)
Описание
The SAML 2.0 Service Provider implementation contains a vulnerability in  the manner in which XML signatures are used to certify security assertions. This issue affects multiple vendors of SAML 2.0  implementations, and is not SAP specific. A malicious user can intercept  or issue one signed assertion, and use an XML signature wrapping attack  to gain higher privileges or impersonate another user. This means that  there is a risk of information disclosure, data tampering and system unavailability as a result of this vulnerability.
Как исправить
Apply the patches in the note according to the used version and Service Pack level.
Ссылки