exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

NetIQ Access Manager 4.0 SP1 XXE Injection

NetIQ Access Manager 4.0 SP1 XXE Injection
Posted Jun 30, 2015
Authored by MustLive

NetIQ Access Manager is vulnerable to XXE injection attacks.

tags | exploit, xxe
SHA-256 | 5ab83fb7455997ac3fe10dc835a9bc56e92d52e2ce04391ac1b7bb994f39d5dc

NetIQ Access Manager 4.0 SP1 XXE Injection

Change Mirror Download
Hello list!

I'll give you additional information concerning advisory Multiple high risk
vulnerabilities in NetIQ Access Manager
(http://securityvulns.ru/docs31510.html). There are five different
vulnerabilities in the advisory. For my attack it's needed to use only one
vulnerability, XML External Entities Injection (XXE), to conduct attacks on
other web sites from target host.

-------------------------
Affected products:
-------------------------

NetIQ Access Manager version 4.0 SP1 and previous versions.

-------------------------
Affected vendors:
-------------------------

Novell.

----------
Details:
----------

NetIQ Access Manager is vulnerable to XXE Injection.

Besides standard vectors of attacks with XXE Injection vulnerabilities (such
as local file inclusion), which are usually mentioned in advisories, XXE
Injection also allows to conduct attacks on other sites. And with using
DAVOSET (DDoS attacks via other sites execution tool) it's possible to
automate such attacks.

XML External Entities (XXE) (WASC-43):

https://site:8443/nps/servlet/webacc?taskId=fw.PreviewObjectFilter&nextState=initialState&merge=fw.TCPreviewFilter&query=<!DOCTYPE+request+[%0a<!ENTITY+xxe+SYSTEM+"http://target">%0a]><query><container>%26xxe%3b</container><subclasses>false</subclasses></query>

I wrote about such attacks in my 2012's article "Using XML External Entities
(XXE) for attacks on other sites"
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2012-August/008481.html)
and 2013's "Using XXE vulnerabilities for attacks on other sites"
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-August/008887.html).
As I described in my articles, XXE vulnerabilities can be used for
conducting CSRF and DoS attacks on other sites (and at using multiple web
sites it's possible to conduct DDoS attacks). And my tool DAVOSET can be
used for conducting such attacks via XXE vulnerabilities.

Video demonstration of DAVOSET: http://www.youtube.com/watch?v=RKi35-f346I

So all vulnerable versions of NetIQ Access Manager can be used for attacks
on other sites via XXE Injection.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close