CVE-2018-1443: Medium severity oracle access manager vulnerability
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1443?
CVE-2018-1443 is an XML parsing vulnerability that affects IBM SAML-based single sign-on (SSO) systems.
Which IBM products are affected by CVE-2018-1443?
IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2 are affected by CVE-2018-1443.
What is the severity of CVE-2018-1443?
CVE-2018-1443 has a severity rating of medium with a CVSS score of 5.9.
How can an attacker exploit CVE-2018-1443?
An attacker with authenticated access can exploit CVE-2018-1443 to trick SAML systems into authenticating as a different user.
How can I mitigate CVE-2018-1443?
To mitigate CVE-2018-1443, update IBM Security Access Manager to version 9.0.5 or later, and update IBM Tivoli Federated Identity Manager to version 6.2.3 or later.