exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

NetIQ Access Manager 4.0 SP1 XXE Injection

NetIQ Access Manager 4.0 SP1 XXE Injection
Posted Jun 30, 2015
Authored by MustLive

NetIQ Access Manager is vulnerable to XXE injection attacks.

tags | exploit, xxe
SHA-256 | 5ab83fb7455997ac3fe10dc835a9bc56e92d52e2ce04391ac1b7bb994f39d5dc

NetIQ Access Manager 4.0 SP1 XXE Injection

Change Mirror Download
Hello list!

I'll give you additional information concerning advisory Multiple high risk
vulnerabilities in NetIQ Access Manager
(http://securityvulns.ru/docs31510.html). There are five different
vulnerabilities in the advisory. For my attack it's needed to use only one
vulnerability, XML External Entities Injection (XXE), to conduct attacks on
other web sites from target host.

-------------------------
Affected products:
-------------------------

NetIQ Access Manager version 4.0 SP1 and previous versions.

-------------------------
Affected vendors:
-------------------------

Novell.

----------
Details:
----------

NetIQ Access Manager is vulnerable to XXE Injection.

Besides standard vectors of attacks with XXE Injection vulnerabilities (such
as local file inclusion), which are usually mentioned in advisories, XXE
Injection also allows to conduct attacks on other sites. And with using
DAVOSET (DDoS attacks via other sites execution tool) it's possible to
automate such attacks.

XML External Entities (XXE) (WASC-43):

https://site:8443/nps/servlet/webacc?taskId=fw.PreviewObjectFilter&nextState=initialState&merge=fw.TCPreviewFilter&query=<!DOCTYPE+request+[%0a<!ENTITY+xxe+SYSTEM+"http://target">%0a]><query><container>%26xxe%3b</container><subclasses>false</subclasses></query>

I wrote about such attacks in my 2012's article "Using XML External Entities
(XXE) for attacks on other sites"
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2012-August/008481.html)
and 2013's "Using XXE vulnerabilities for attacks on other sites"
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-August/008887.html).
As I described in my articles, XXE vulnerabilities can be used for
conducting CSRF and DoS attacks on other sites (and at using multiple web
sites it's possible to conduct DDoS attacks). And my tool DAVOSET can be
used for conducting such attacks via XXE vulnerabilities.

Video demonstration of DAVOSET: http://www.youtube.com/watch?v=RKi35-f346I

So all vulnerable versions of NetIQ Access Manager can be used for attacks
on other sites via XXE Injection.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close