VDB
RHSA-2017%3A3220
RHSA-2017%3A3220
PUBLISHED
CVSS 6.5 MEDIUM
It was found that while parsing the SAML messages the StaxParserUtil class of Picketlink replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.4 |
Timeline
- Nov 14, 2017 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2017:3220 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/documentation/en/jboss-enterprise-application-platform/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1410481 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_3220.json advisory
- https://access.redhat.com/security/cve/CVE-2017-2582 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-2582 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-2582 advisory