Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43338
HistorySep 21, 2023 - 11:34 a.m.

Authentication Bypass

2023-09-2111:34:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
sustainsys.saml2
vulnerability
authentication bypass
identity provider
saml2
response
issuer
validation check
stored state
application security

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

24.5%

Sustainsys.Saml2 is vulnerable to Authentication Bypass. The vulnerability is caused by a missing validation check for the issuer of the Saml2 assertion in a Saml2 response and issuer identified in the stored request state. This can lead to a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider and it can also lead to a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted only if they rely on these two features - issuer of the generated identity and claims or items in the stored request state (AuthenticationProperties).

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

24.5%

Related for VERACODE:43338