PT-2022-15897 · Sysaid · Sysaid

Published

2022-06-24

·

Updated

2022-07-07

·

CVE-2022-23170

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SysAid - Okta SSO integration (affected versions not specified)
Description The issue concerns an XML External Entity Injection vulnerability. An unauthenticated attacker can exploit this by sending a malformed POST request to the identity provider endpoint. The attacker can extract the endpoint by decoding the SAMLRequest parameter's value and searching for the AssertionConsumerServiceURL parameter's value. This often allows the attacker to view files on the application server filesystem and interact with back-end or external systems. In some situations, the attacker can escalate the attack to compromise the underlying server or back-end infrastructure by leveraging the vulnerability to perform server-side request forgery (SSRF) attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23170

Affected Products

Sysaid