PT-2022-15897 · Sysaid · Sysaid
Published
2022-06-24
·
Updated
2022-07-07
·
CVE-2022-23170
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SysAid - Okta SSO integration (affected versions not specified)
Description
The issue concerns an XML External Entity Injection vulnerability. An unauthenticated attacker can exploit this by sending a malformed POST request to the identity provider endpoint. The attacker can extract the endpoint by decoding the
SAMLRequest parameter's value and searching for the AssertionConsumerServiceURL parameter's value. This often allows the attacker to view files on the application server filesystem and interact with back-end or external systems. In some situations, the attacker can escalate the attack to compromise the underlying server or back-end infrastructure by leveraging the vulnerability to perform server-side request forgery (SSRF) attacks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sysaid