CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
Percentile
99.9%
The XML Signature specification allows for HMAC truncation, which may allow a remote attacker to bypass authentication.
XML Signature Syntax and Processing (XMLDsig) is a W3C recommendation for providing integrity, message authentication, and/or signer authentication services for data. XMLDsig is commonly used by web services such as SOAP. The XMLDsig recommendation includes support for HMAC truncation, as specified in RFC2104. However, the XMLDsig specification does not follow the RFC2104 recommendation to not allow truncation to less than half of the length of the hash output or less than 80 bits. When HMAC truncation is under the control of an attacker this can result in an effective authentication bypass. For example, by specifying an HMACOutputLength of 1
, only one bit of the signature is verified. This can allow an attacker to forge an XML signature that will be accepted as valid.
This vulnerability can allow an attacker to bypass the authentication mechanism provided by the XML Signature specification.
Apply an update
Please check with your vendor for available updates. Erratum E03 for the XMLDsig recommendation has been added, which specifies minimum values for HMAC truncation.
466161
Filter by status: All Affected Not Affected Unknown
Filter by content: __ Additional information available
__ Sort by: Status Alphabetical
Expand all
Javascript is disabled. Click here to view vendors.
Updated: July 14, 2009
Statement Date: July 10, 2009
Affected
We have not received a statement from the vendor.
The Apache XML Security Java implementation (<http://santuario.apache.org>) is affected. The vulnerability will be fixed in version 1.4.3. The final release of version 1.4.3 is targeted for mid-late July. Please subscribe to the mailing
list (<http://santuario.apache.org/mail-lists.html>) for more details.
Notified: July 09, 2009 Updated: July 10, 2009
Statement Date: July 09, 2009
Affected
We have not received a statement from the vendor.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 14, 2009
Statement Date: July 15, 2009
Affected
We have not received a statement from the vendor.
The vendor has not provided us with any further information regarding this vulnerability.
Please see Debian Security Advisory DSA-1833-1.
If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23466161 Feedback>).
Notified: July 09, 2009 Updated: July 14, 2009
Statement Date: July 14, 2009
Affected
IBM has issued the following Flash for WebSphere Application Server which describes resolutions available:
Possible security exposure with XML digital signature with IBM WebSphere Application Server (PK80596 and PK80627):
http://www.ibm.com/support/docview.wss?rs=180&uid=swg21384925
The vendor has not provided us with any further information regarding this vulnerability.
Updated: July 10, 2009
Statement Date: July 10, 2009
Affected
We have not received a statement from the vendor.
Our implementation is vulnerable and a new version* of Mono 2.4.2.2 will be available on (or soon after) July 14th 2PM EST.
The information about this vulnerability will be added to
<http://www.mono-project.com/Vulnerabilities>
at the same time.
Updated: July 13, 2009
Statement Date: July 13, 2009
Affected
We have not received a statement from the vendor.
Oracle WebLogic Server (Web Services Component) and Oracle Secure Development Toolkit/Oracle Web Services Manager are impacted by this issue. Please check <http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html> for more information.
Updated: July 14, 2009
Statement Date: July 14, 2009
Affected
We have not received a statement from the vendor.
RSA products potentially impacted by this vulnerability are (RSA Security Advisories are accessible only by the customers):
* RSA(r) BSAFE Cert-J and SSL-J - Security Advisory:
* RSA(r) Federated Identity Manager - Security Advisory:
The updates and patches are available on the RSA SecurCare Online
website ().
Notified: July 09, 2009 Updated: August 05, 2009
Statement Date: July 14, 2009
Affected
We have not received a statement from the vendor.
The XML Digital Signature implementation included with the Java Runtime Environment is affected and may allow authentication to be bypassed. Applications that validate HMAC-based XML digital signatures may be vulnerable to this type of attack. This vulnerability cannot be exploited by an untrusted applet or Java Web Start application.
This issue can occur in the following Java SE and Java SE for Business releases for Windows, Solaris, and Linux:
JDK and JRE 6 Update 14 and earlier
Note: JDK and JRE 5.0, and SDK and JRE 1.4.2 and 1.3.1 are not affected.
This issue will be addressed with Sun’s upcoming Java SE security updates which are targeted to be released in late July 2009.
Please see Sun Alert 263429 for details and updated JRE versions.
If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23466161 Feedback>).
Updated: July 10, 2009
Affected
We have not received a statement from the vendor.
The library is affected and the patched release will be available on July 14 at <http://www.aleksey.com/xmlsec/downloads.html>
Notified: July 09, 2009 Updated: July 14, 2009
Statement Date: July 15, 2009
Not Affected
Force10 Networks products are not vulnerable to this threat.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 20, 2009
Statement Date: July 17, 2009
Not Affected
Peplink products do not implement XMLDsig.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 10, 2009
Statement Date: July 09, 2009
Not Affected
We have not received a statement from the vendor.
Q1 Labs products are not affected by this Vulnerability.
Notified: July 09, 2009 Updated: July 13, 2009
Statement Date: July 13, 2009
Not Affected
No SCO products are affected by this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 14, 2009
Statement Date: July 14, 2009
Not Affected
We have not received a statement from the vendor.
VMware is not affected by this vulnerability.
Notified: July 09, 2009 Updated: July 13, 2009
Statement Date: July 13, 2009
Not Affected
Wind River’s VxWorks product is not vulnerable.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 10, 2009
Statement Date: July 09, 2009
Not Affected
m0n0wall is not affected by this vulnerability as it does not use XMLDsig anywhere.
The vendor has not provided us with any further information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: June 22, 2009 Updated: June 22, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: February 18, 2009 Updated: February 18, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Notified: July 09, 2009 Updated: July 09, 2009
Unknown
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
View all 100 vendors __View less vendors __
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
Thanks to Thomas Roessler of the W3C for reporting this vulnerability.
This document was written by Will Dormann.
CVE IDs: | CVE-2009-0217 |
---|---|
Severity Metric: | 8.16 Date Public: |
blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161
msdn.microsoft.com/en-us/library/ms996502.aspx
rdist.root.org/2009/07/19/xmldsig-welcomes-all-signatures/
santuario.apache.org/download.html
tools.ietf.org/html/rfc2104#section-5
www.aleksey.com/xmlsec/downloads.html
www.ibm.com/support/docview.wss?rs=180&uid=swg21384925
www.mono-project.com/Vulnerabilities
www.oasis-open.org/specs/index.php#wss
www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html
www.rsa.com/blog/blog_entry.aspx?id=1492
www.w3.org/2000/xp/Group/
www.w3.org/2008/06/xmldsigcore-errata.html#e03
www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html
www.w3.org/TR/xmldsig-core/
www.w3.org/TR/xmldsig-core/#sec-HMAC