Vulnerability Description
CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siteminder Agent For Sharepoint | 2010 | All versions |
| Siteminder Federation | 12.0 | All versions |
| Siteminder Federation | 12.1 | - |
| Siteminder Federation | 12.5 | All versions |
| Siteminder Federation | R6.0 | All versions |
| Siteminder For Secure Proxy Server | 12.0 | All versions |
| Siteminder For Secure Proxy Server | 12.5 | All versions |
| Siteminder For Secure Proxy Server | 6.0 | All versions |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2013-03/0118.html
- http://secunia.com/advisories/52610Vendor Advisory
- http://www.securityfocus.com/bid/58609
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7B53E50CBD-
- http://archives.neohapsis.com/archives/bugtraq/2013-03/0118.html
- http://secunia.com/advisories/52610Vendor Advisory
- http://www.securityfocus.com/bid/58609
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7B53E50CBD-
FAQ
What is CVE-2013-2279?
CVE-2013-2279 is a vulnerability with a CVSS score of 7.5 (HIGH). CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify...
How severe is CVE-2013-2279?
CVE-2013-2279 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2279?
Check the references section above for vendor advisories and patch information. Affected products include: Siteminder Agent For Sharepoint 2010, Siteminder Federation 12.0, Siteminder Federation 12.1, Siteminder Federation 12.5, Siteminder Federation R6.0.