Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAML 2.0 possible XML Signature wrapping attack, SAP security note 1753376

SAP Note 1753376

SAP security note 1753376, “SAML 2.0: possible XML Signature wrapping attack”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Messages sent and received by the SAML 2.0 Service Provider can be manipulated by a malicious user to allow them to perform unauthorized actions on behalf of another user, thereby generally circumventing the integrity protection provided by the service.

Solution

Apply the patches in the note according to the used version and Service Pack level.

Reason and prerequisites

The SAML 2.0 Service Provider implementation contains a vulnerability in the manner in which XML signatures are used to certify security assertions. This issue affects multiple vendors of SAML 2.0 implementations and is not SAP specific. A malicious user can intercept or issue one signed assertion and use an XML signature wrapping attack to gain higher privileges or impersonate another user. This means that there is a risk of information disclosure, data tampering, and system unavailability as a result of this vulnerability.

Affected components

  • SECURITY-EXT: 7.20 to 7.20
  • SECURITY-EXT: 7.30 to 7.30
  • SECURITY-EXT: 7.31 to 7.31

Full note on SAP: SAP Support Launchpad note 1753376

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More