CVE-2013-2279
CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.
Published:Mar 21, 2013
Last Modified:Apr 11, 2025
EPS:Mar 21, 2013
EPSS Score:0.00585
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Siteminder Agent For Sharepoint
Product
2010
Siteminder Agent For Sharepoint
2010
Vendor
Siteminder Federation
Product
12.0
Siteminder Federation
12.0
Vendor
Siteminder Federation
Product
12.1
Siteminder Federation
12.1
Vendor
Siteminder Federation
Product
12.5
Siteminder Federation
12.5
Vendor
Siteminder Federation
Product
R6.0
Siteminder Federation
R6.0
Vendor
Siteminder For Secure Proxy Server
Product
12.0
Siteminder For Secure Proxy Server
12.0
Vendor
Siteminder For Secure Proxy Server
Product
12.5
Siteminder For Secure Proxy Server
12.5
Vendor
Siteminder For Secure Proxy Server
Product
6.0
Siteminder For Secure Proxy Server
6.0
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
