Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjw4-77m8-grj2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.

CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.

EPSS

Процентиль: 69%
0.00585
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 13 лет назад

CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.

EPSS

Процентиль: 69%
0.00585
Низкий

Дефекты

CWE-20