CVE-2022-35202 Information

Description

A security issue in Sitevision version 10.3.1 and older allows a remote attacker in certain (non-default) scenarios to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity auto-generated password.

Reference

https://developer.sitevision.se/archives/release-notes/release-notes/2022-05-06-release-notes-sitevision-10.3 https://www.shelltrail.com/research/how-auto-generated-passwords-in-sitevision-leads-to-signing-key-leakage-cve-2022-35202/

Share on: