Unknown · Sitevision · CVE-2022-35202
**Name of the Vulnerable Software and Affected Versions**
Sitevision versions 10.3.1 and earlier
**Description**
A security issue in Sitevision allows a remote attacker, in certain non-default scenarios, to gain access to the private keys used for signing SAML authentication requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password.
**Recommendations**
For Sitevision versions 10.3.1 and earlier, consider disabling WebDAV access to the Java keystore as a temporary workaround until a patch is available. Restrict access to the keystore to minimize the risk of exploitation. Avoid using auto-generated passwords for the keystore. At the moment, there is no information about a newer version that contains a fix for this vulnerability.