SB2018030707 - Security restrictions bypass in IBM Security Access Manager
Published: March 7, 2018
Security Bulletin ID
SB2018030707
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) XXE attack (CVE-ID: CVE-2018-1443)
The vulnerability allows a remote authenticated attacker to perform XXE attack and bypass security restrictions.The vulnerability exists in SAML-based single sign-on (SSO) systems due to improper handling of XML External Entity (XXE) entries when parsing an XML file. A remote attacker can trick SAML systems into authenticating as a different user without knowledge of the victim users password and bypass security restrictions to perform further attacks.
Remediation
Install update from vendor's website.