Red Hat Bugzilla – Bug 865169
CVE-2012-5352 JOSSO: vulnerable to authentication bypass and forged messages due to a Signature exclusion attack
Last modified: 2012-10-11 20:26:24 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5352 to the following vulnerability: Name: CVE-2012-5352 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5352 Assigned: 20121009 Reference: http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
Statement: Not vulnerable. The JOSSO server component which exposes this flaw is not shipped in any Red Hat product. The JOSSO agent shipped with JBoss Enterprise Portal Platform does not expose this flaw.