The following issues have been reported in the Advanced Authentication admin portal:
VAPT vulnerability "Host Header Injection" While accessing admin URL https://<host>/<port>/arcotadmin/adminlogin.htm, its observed that application is getting redirected to other domains by changing the host header value. Recommendation: Only expected hostname should be allowed. Reject requests with unexpected or malformed Host headers.
VAPT vulnerability "Sensitive data exposure" While accessing admin URL https://<host>/<port>/arcotadmin/adminlogin.htm, its observed that token is transmitted in URL. Recommendation: Sensitive data should not travel in URL by GET method.
Advanced Search issue in Symantec-AdvAuth-9.1.5.1-DE660677-HotFix The Advanced Search menu is not working in Symantec-AdvAuth-9.1.5.1-DE660677-HotFix, and an IndexOutOfBoundsException is encountered in the admin portal.
Inactive users search displays active users While fetching for "User Administrator - Inactive" criterion, second page was available for navigation. On clicking for page 2, below error message was received, same as the previous iteration of testing. "Invalid request receivedInvalid property 'userSearchDisplayList[1]' of bean class [com.arcot.adminconsole.admin.web.usermgmt.UserSearchResultsBean]: Index of out of bounds in property path 'userSearchDisplayList[1]'; nested exception is java.lang.IndexOutOfBoundsException: Index: 1, Size: 1"
Environment
Symantec Advanced Authentication 9.1.5.1
Resolution
To resolve this issue, we recommend applying the following patch: