VDB
RHSA-2018:2740
RHSA-2018:2740
PUBLISHED
CVSS 6.5 MEDIUM
It was found that while parsing the SAML messages the StaxParserUtil class of Picketlink replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.4 |
Timeline
- Sep 24, 2018 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/6.4/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1570200 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1573391 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1578830 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1580440 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1594389 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1606334 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1610355 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1610742 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1611770 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1614448 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2740.json advisory
- https://access.redhat.com/security/cve/CVE-2017-2582 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-2582 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-2582 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1336 advisory
- https://access.redhat.com/errata/RHSA-2018:2740 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1261190 issue
…and 16 more