Clearpass Policy Manager accepted expired SAML tickets
-
Tomas Rzepka
- Published: 23 May 2022
- Type: Improper Authentication
- Severity: Medium
Aruba Clearpass Policy Manager
CVE-2022-23669
WithSecure identified an authentication vulnerability that arises when SAML is setup as the authentication mechanism for Clearpass Policy Manager portal. It was possible to reuse expired SAML tickets and get a new valid session token with the privileges of the user that originally requested the SAML ticket. The issue was found in ClearPass Policy Manager 6.10.2, but older versions could also be vulnerable.
An attacker who gains access to a expired SAML ticket may reuse the ticket to gain access to Policy Manager administration portal.
The application did not verify the NotOnOrAfter attribute in the SAML token Conditions element.
According to the vendor, the following base versions can be patched with the corresponding patch.
Date | Action |
---|---|
3 Nov 2021 | Notified Aruba Networks about the identified vulnerability |
1 Dec 2021 | Vendor acknowledged issue |
2 Mar 2022 | Vendor release fixed version |
4 May 2022 | Vendor publish advisory https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-007.txt |
23 May 2022 | WithSecure publishes advisory |