PT-2009-6690 · Oracle+6 · Sun Jdk/Jre+8

Scott Cantor

·

Published

1970-01-01

·

Updated

2022-05-02

·

CVE-2009-0217

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions XML Security Library versions prior to 1.2.12 Mono versions prior to 2.4.2.2 IBM WebSphere Application Server versions prior to 6.0.2.33, 6.1.0.23, and 7.0.0.1 Oracle Application Server versions 10.1.2.3, 10.1.3.4, and 10.1.4.3IM Oracle WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6 Microsoft .NET Framework versions 3.0 through 3.0 SP2, 3.5, and 4.0 Sun JDK and JRE Update 14 and earlier
Description The vulnerability is related to the W3C XML Signature Syntax and Processing recommendation, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits. This can lead to data tampering and disruption of protected information. The vulnerability can be exploited remotely.
Recommendations For XML Security Library versions prior to 1.2.12, update to version 1.2.12 or later. For Mono versions prior to 2.4.2.2, update to version 2.4.2.2 or later. For IBM WebSphere Application Server versions prior to 6.0.2.33, 6.1.0.23, and 7.0.0.1, update to the latest version. For Oracle Application Server versions 10.1.2.3, 10.1.3.4, and 10.1.4.3IM, update to the latest version. For Oracle WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6, update to the latest version. For Microsoft .NET Framework versions 3.0 through 3.0 SP2, 3.5, and 4.0, update to the latest version. For Sun JDK and JRE Update 14 and earlier, update to the latest version. As a temporary workaround, consider restricting access to HMAC-based signature methods until a patch is available.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02869
BDU:2015-02870
BDU:2015-02871
BDU:2015-02872
CVE-2009-0217
DSA-1849-1
DSA-1995-1
DTSA-205-1
GHSA-8HFM-837H-HJG5
HPSBUX02476
RHSA-2009:1200
RHSA-2009:1201
RHSA-2009:1428
RHSA-2009:1636
RHSA-2009:1637
RHSA-2009:1649
RHSA-2009:1650
RHSA-2009:1694
RHSA-2009_1201
RHSA-2009_1428
RHSA-2010:0043

Affected Products

.Net Framework
Hp-Ux
Ibm Websphere Application Server
Mono
Oracle Application Server
Oracle Weblogic Server
Red Hat
Sun Jdk/Jre
Xml Security Library