First published: Thu Mar 08 2018(Updated: )
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager | >=9.0.0<=9.0.4 | |
IBM Tivoli Federated Identity Manager | =6.2.0 | |
IBM Tivoli Federated Identity Manager | =6.2.1 | |
IBM Tivoli Federated Identity Manager | =6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1443 is an XML parsing vulnerability that affects IBM SAML-based single sign-on (SSO) systems.
IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2 are affected by CVE-2018-1443.
CVE-2018-1443 has a severity rating of medium with a CVSS score of 5.9.
An attacker with authenticated access can exploit CVE-2018-1443 to trick SAML systems into authenticating as a different user.
To mitigate CVE-2018-1443, update IBM Security Access Manager to version 9.0.5 or later, and update IBM Tivoli Federated Identity Manager to version 6.2.3 or later.