SB2018022712 - XXE attack in SAML libraries
Published: February 27, 2018
Security Bulletin ID
SB2018022712
Severity
Low
Patch available
YES
Number of vulnerabilities
4
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) XXE attack (CVE-ID: CVE-2017-11430)
The vulnerability allows a remote attacker to perform XXE attack.The vulnerability exists due to an implementation flaw in the SAML open-source library. A remote attacker can add or modify specially crafted XML data, modify digital signatures of user attribute data and impersonate a user or obtain potentially sensitive information.
2) XXE attack (CVE-ID: CVE-2017-11429)
The vulnerability allows a remote authenticated attacker to perform XXE attack.The vulnerability exists due to an implementation flaw in the saml2-js open-source library. A remote attacker can add or modify specially crafted XML data, modify digital signatures of user attribute data and impersonate a user or obtain potentially sensitive information.
3) XXE attack (CVE-ID: CVE-2017-11428)
The vulnerability allows a remote authenticated attacker to perform XXE attack.The vulnerability exists due to an implementation flaw in the ruby-saml open-source library. A remote attacker can add or modify specially crafted XML data, modify digital signatures of user attribute data and impersonate a user or obtain potentially sensitive information.
4) XXE attack (CVE-ID: CVE-2017-11427)
The vulnerability allows a remote authenticated attacker to perform XXE attack.The vulnerability exists due to an implementation flaw in the python-saml open-source library. A remote attacker can add or modify specially crafted XML data, modify digital signatures of user attribute data and impersonate a user or obtain potentially sensitive information.
Remediation
Install update from vendor's website.