CVE Feed

    Dashboard / CVE / CVE-2013-2279

    CVE-2013-2279

    CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.

    Published:Mar 21, 2013
    Last Modified:Apr 11, 2025
    EPS:Mar 21, 2013
    EPSS Score:0.00585
    CVSS Score:7.5

    Affected Products

    Vendor
    Siteminder Agent For Sharepoint
    Product
    2010
    Vendor
    Siteminder Federation
    Product
    12.0
    Vendor
    Siteminder Federation
    Product
    12.1
    Vendor
    Siteminder Federation
    Product
    12.5
    Vendor
    Siteminder Federation
    Product
    R6.0
    Vendor
    Siteminder For Secure Proxy Server
    Product
    12.0
    Vendor
    Siteminder For Secure Proxy Server
    Product
    12.5
    Vendor
    Siteminder For Secure Proxy Server
    Product
    6.0

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High