CA SiteMinder Header Processing Lets Remote Users Impersonate Other Users
|
SecurityTracker Alert ID: 1025423 |
SecurityTracker URL: http://securitytracker.com/id/1025423
|
CVE Reference:
CVE-2011-1718
(Links to External Site)
|
Updated: May 20 2011
|
Original Entry Date: Apr 21 2011
|
Impact:
Host/resource access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): R6 Web Agents prior to R6 SP6 CR2, R12 Web Agents prior to R12 SP3 CR2
|
Description:
A vulnerability was reported in CA SiteMinder. A remote user can impersonate another user.
A remote user can supply specially crafted multi-line headers to impersonate another user.
The vendor notes that only IIS 6.0 Web Agents are affected and that IIS 7 Web Agents are not affected.
April King reported this vulnerability.
|
Impact:
A remote user can impersonate another user.
|
Solution:
The vendor has issued a fix.
CA SiteMinder R6:
Upgrade to R6 SP6 CR2 or later
CA SiteMinder R12:
Upgrade to R12 SP3 CR2 or later
|
Vendor URL: www.ca.com/ (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Subject: CA20110420-01: Security Notice for CA SiteMinder
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
CA20110420-01: Security Notice for CA SiteMinder
Issued: April 20, 2011
CA Technologies support is alerting customers to a security risk
associated with CA SiteMinder. A vulnerability exists that can allow a
malicious user to impersonate another user. CA Technologies has
issued patches to address the vulnerability.
The vulnerability, CVE-2011-1718, is due to improper handling of
multi-line headers. A malicious user can send specially crafted data
to impersonate another user.
Risk Rating
Medium
Platform
Windows
Affected Products
CA SiteMinder R6 Web Agents prior to R6 SP6 CR2
CA SiteMinder R12 Web Agents prior to R12 SP3 CR2
How to determine if the installation is affected
Check the Web Agent log to obtain the installed release version. Note
that the "webagent.log" file name is configurable by the SiteMinder
administrator.
Solution
CA has issued patches to address the vulnerability.
CA SiteMinder R6:
Upgrade to R6 SP6 CR2 or later
CA SiteMinder R12:
Upgrade to R12 SP3 CR2 or later
CR releases can be found on the CA SiteMinder Hotfix / Cumulative
Release page:
(URL may wrap)
support.ca.com/irj/portal/anonymous/phpdocs?filePath=0/5262/5262_fixinde
x.h
tml
References
CVE-2011-1718 - CA SiteMinder Multi-line Header Vulnerability
Acknowledgement
April King (april@twoevils.org)
Change History
Version 1.0: Initial Release
If additional information is required, please contact CA Technologies
Support at https://support.ca.com.
If you discover a vulnerability in a CA Technologies product, please
report your findings to the CA Technologies Product Vulnerability
Response Team.
support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=177782
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.9.1 (Build 287)
Charset: utf-8
wj4DBQFNr6uXeSWR3+KUGYURAvcnAKCVdxdKNawQQC/M/wK9tDk5gD6jzQCTByZ/
X9MjXhbKg9eeMFDPXdrxlA==
=nwb+
-----END PGP SIGNATURE-----
|
|