CVE Database
/

CVE-2009-0217

Back to search

CVE-2009-0217

Published: Jul 14, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2009:1428
vendor-advisory
x_refsource_REDHAT
ADV-2009-3122
vdb-entry
x_refsource_VUPEN
60799
third-party-advisory
x_refsource_SECUNIA
GLSA-201408-19
vendor-advisory
x_refsource_GENTOO
PK80596
vendor-advisory
x_refsource_AIXAPAR
RHSA-2009:1200
vendor-advisory
x_refsource_REDHAT
35776
third-party-advisory
x_refsource_SECUNIA
36162
third-party-advisory
x_refsource_SECUNIA
36494
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2543
vdb-entry
x_refsource_VUPEN
35858
third-party-advisory
x_refsource_SECUNIA
38695
third-party-advisory
x_refsource_SECUNIA
269208
vendor-advisory
x_refsource_SUNALERT
DSA-1995
vendor-advisory
x_refsource_DEBIAN
HPSBUX02476
vendor-advisory
x_refsource_HP
35853
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1637
vendor-advisory
x_refsource_REDHAT
RHSA-2009:1694
vendor-advisory
x_refsource_REDHAT
35852
third-party-advisory
x_refsource_SECUNIA
35854
third-party-advisory
x_refsource_SECUNIA
34461
third-party-advisory
x_refsource_SECUNIA
1020710
vendor-advisory
x_refsource_SUNALERT
USN-903-1
vendor-advisory
x_refsource_UBUNTU
35671
vdb-entry
x_refsource_BID
ADV-2010-0366
vdb-entry
x_refsource_VUPEN
55907
vdb-entry
x_refsource_OSVDB
MDVSA-2009:209
vendor-advisory
x_refsource_MANDRIVA
SUSE-SA:2010:017
vendor-advisory
x_refsource_SUSE
38567
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-8329
vendor-advisory
x_refsource_FEDORA
263429
vendor-advisory
x_refsource_SUNALERT
SSRT090250
vendor-advisory
x_refsource_HP
ADV-2009-1900
vdb-entry
x_refsource_VUPEN
1022561
vdb-entry
x_refsource_SECTRACK
37671
third-party-advisory
x_refsource_SECUNIA
VU#466161
third-party-advisory
x_refsource_CERT-VN
1022567
vdb-entry
x_refsource_SECTRACK
RHSA-2009:1636
vendor-advisory
x_refsource_REDHAT
PK80627
vendor-advisory
x_refsource_AIXAPAR
RHSA-2009:1649
vendor-advisory
x_refsource_REDHAT
TA09-294A
third-party-advisory
x_refsource_CERT
ADV-2009-1909
vdb-entry
x_refsource_VUPEN
ADV-2010-0635
vdb-entry
x_refsource_VUPEN
38568
third-party-advisory
x_refsource_SECUNIA
36180
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-8456
vendor-advisory
x_refsource_FEDORA
USN-826-1
vendor-advisory
x_refsource_UBUNTU
37841
third-party-advisory
x_refsource_SECUNIA
35855
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-8473
vendor-advisory
x_refsource_FEDORA
36176
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:7158
vdb-entry
signature
x_refsource_OVAL
ADV-2009-1908
vdb-entry
x_refsource_VUPEN
FEDORA-2009-8337
vendor-advisory
x_refsource_FEDORA
41818
third-party-advisory
x_refsource_SECUNIA
1022661
vdb-entry
x_refsource_SECTRACK
37300
third-party-advisory
x_refsource_SECUNIA
ADV-2009-1911
vdb-entry
x_refsource_VUPEN
APPLE-SA-2009-09-03-1
vendor-advisory
x_refsource_APPLE
SUSE-SA:2009:053
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:8717
vdb-entry
signature
x_refsource_OVAL
RHSA-2009:1201
vendor-advisory
x_refsource_REDHAT
TA10-159B
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:10186
vdb-entry
signature
x_refsource_OVAL
55895
vdb-entry
x_refsource_OSVDB
MS10-041
vendor-advisory
x_refsource_MS
38921
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1650
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now