Openssl vulnerabilies CVE-2022-3602 and CVE-2022-3786 in SiteMinder
search cancel

Openssl vulnerabilies CVE-2022-3602 and CVE-2022-3786 in SiteMinder

book

Article ID: 253745

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

Concerned whether the following CVE's for OpenSSL impact any Siteminder components, since Siteminder bundles OpenSSL with the Policy Server, Access Gateway and the Agent for Sharepoint.

CVE-2022-3786: X.509 Email Address Variable Length Buffer Overflow

CVE-2022-3602: X.509 Email Address 4-byte Buffer Overflow

  • Versions Impacted: Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6) 

 

Environment

PRODUCT: Symantec Siteminder

COMPONENT: ALL

OS: ANY

Cause

CVE-2022-3786: X.509 Email Address Variable Length Buffer Overflow

CVE-2022-3602: X.509 Email Address 4-byte Buffer Overflow

  • Versions Impacted: Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6) 

Resolution

There are no Siteminder components impacted by these CVE's.  Siteminder ships with OpenSSL 1.0.2 up to r12.8.8.1.  These CVE's are for OpenSSL 3.0.x which are not bundled on any Siteminder components up to r12.8.8.1.

Additional Information