CVE-2009-0217

Oracle Application Server <10.1.4.3IM - XML Signature Processing

Title source: llm
STIX 2.1

Description

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

References (86)

Core 86
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1428.html
Various Sources x_refsource_confirm
http://www.aleksey.com/xmlsec/
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/WDON-7TY529
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3122
Various Sources x_refsource_confirm
https://issues.apache.org/bugzilla/show_bug.cgi?id=47526
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60799
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1200.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35776
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36162
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36494
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2543
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35858
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38695
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-269208-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-1995
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=125787273209737&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35853
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1637.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1694.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35852
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35854
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34461
Vendor Advisory x_refsource_confirm
http://www.mono-project.com/Vulnerabilities
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020710.1-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-903-1
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35671
Various Sources x_refsource_confirm
https://issues.apache.org/bugzilla/show_bug.cgi?id=47527
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0366
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55907
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:209
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38567
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1900
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022561
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37671
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/466161
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022567
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1636.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1649.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-294A.html
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1909
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0635
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38568
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36180
Vendor Advisory x_refsource_confirm
http://www.w3.org/2008/06/xmldsigcore-errata.html#e03
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/826-1/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37841
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35855
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36176
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7158
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1908
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg21384925
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41818
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022661
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37300
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1911
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8717
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1201.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-159B.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10186
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55895
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38921
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1650.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=511915

Scores

EPSS 0.0635
EPSS Percentile 92.9%

Details

Status published
Products (49)
ibm/websphere_application_server 6.0
ibm/websphere_application_server 6.0.0.1
ibm/websphere_application_server 6.0.0.2
ibm/websphere_application_server 6.0.0.3
ibm/websphere_application_server 6.0.1
ibm/websphere_application_server 6.0.1.1
ibm/websphere_application_server 6.0.1.2
ibm/websphere_application_server 6.0.1.3
ibm/websphere_application_server 6.0.1.5
ibm/websphere_application_server 6.0.1.7
... and 39 more
Published Jul 14, 2009
Tracked Since Feb 18, 2026