VAPT Vulnerabilities and Search issues in Advanced Authentication Admin portal
search cancel

VAPT Vulnerabilities and Search issues in Advanced Authentication Admin portal

book

Article ID: 439867

calendar_today

Updated On:

Products

CA Risk Authentication CA Advanced Authentication CA Advanced Authentication - Risk Authentication (RiskMinder / RiskFort) CA Advanced Authentication - Strong Authentication (AuthMinder / WebFort) CA Strong Authentication

Issue/Introduction

The following issues have been reported in the Advanced Authentication admin portal:

  • VAPT vulnerability "Host Header Injection"
    While accessing admin URL https://<host>/<port>/arcotadmin/adminlogin.htm, its observed that application is getting redirected to other domains by changing the host header value.
    Recommendation: Only expected hostname should be allowed. Reject requests with unexpected or malformed Host headers.

  • VAPT vulnerability "Sensitive data exposure"
    While accessing admin URL https://<host>/<port>/arcotadmin/adminlogin.htm, its observed that token is transmitted in URL.
    Recommendation: Sensitive data should not travel in URL by GET method.

  • Advanced Search issue in Symantec-AdvAuth-9.1.5.1-DE660677-HotFix
    The Advanced Search menu is not working in Symantec-AdvAuth-9.1.5.1-DE660677-HotFix, and an IndexOutOfBoundsException is encountered in the admin portal.

  • Inactive users search displays active users
    While fetching for "User Administrator - Inactive" criterion, second page was available for navigation. On clicking for page 2, below error message was received, same as the previous iteration of testing.
    "Invalid request receivedInvalid property 'userSearchDisplayList[1]' of bean class [com.arcot.adminconsole.admin.web.usermgmt.UserSearchResultsBean]: Index of out of bounds in property path 'userSearchDisplayList[1]'; nested exception is java.lang.IndexOutOfBoundsException: Index: 1, Size: 1"

Environment

Symantec Advanced Authentication 9.1.5.1

Resolution

To resolve this issue, we recommend applying the following patch:

  • Patch: Symantec-AdvAuth-9.1.5.1-DE664309-HotFix

  • Download: Available in the associated KB article.

Attachments

Symantec-AdvAuth-9.1.5.1-DE664309-HotFix.zip get_app