Vulnerability Description
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oneidentity | Cloud Access Manager | < 8.1.4 |
Related Weaknesses (CWE)
References
- https://github.com/FurqanKhan1/CVE-2019-13496ExploitThird Party Advisory
- https://support.oneidentity.com/cloud-access-manager/kb/311391/cloud-access-manaRelease NotesVendor Advisory
- https://github.com/FurqanKhan1/CVE-2019-13496ExploitThird Party Advisory
- https://support.oneidentity.com/cloud-access-manager/kb/311391/cloud-access-manaRelease NotesVendor Advisory
FAQ
What is CVE-2019-13496?
CVE-2019-13496 is a vulnerability with a CVSS score of 8.1 (HIGH). One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a succ...
How severe is CVE-2019-13496?
CVE-2019-13496 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13496?
Check the references section above for vendor advisories and patch information. Affected products include: Oneidentity Cloud Access Manager.