Symantec Identity Portal SAML Signature Bypass on Identity Portal
search cancel

Symantec Identity Portal SAML Signature Bypass on Identity Portal

book

Article ID: 432547

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

While using the Vapp IGA 14.5 GA, integrated IdentityPortal(SP) with PingFederate(IdP) using SAML integration.

On Vulnerability Assessment, found a CRITICAL issue on this integration, where SAML Signature Bypass and SAML Response can be modify as a different user.

Environment

 Vapp IGA 14.5 GA

Cause

In Identity Portal, OpenSAML v2 is used, and it is already EOL, hence suspect this is the root cause of why the SAML signature was able to bypass.  

 

 

Resolution

Even though the SAML assertion is signed, Identity Portal’s OpenSAML v2 implementation does not strictly bind signature validation to identity extraction, allowing assertion tampering and user impersonation.

A Hotfix  HF_IP-14.5.0-20260220140226-SAML_ENCRYPTION_FIX.tgz.gpg is available to address this issue, and initial testing has enabled encryption of SAML Assertion with PingFed

Additional Information

Ref# DE660470