Anaplan Security: Anaplan Statement on SAML Vulnerability
Options
rupert_tagnipes
Member, ALL USERS, Employee Posts: 4 Master Anaplanner of the Year
in Security
Anaplan Security Engineering has performed a thorough investigation of the following vulnerability: Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal.
Anaplan Security Engineering confirms that its SAML implementation is not vulnerable to such attacks as described in the following CVE’s:
- Reference: https://www.kb.cert.org/vuls/id/475445
- CVE IDs: CVE-2017-11427 CVE-2017-11428 CVE-2017-11429 CVE-2017-11430 CVE-2018-0489
- Vulnerability Note VU#475445 - Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
- Vulnerability Description: Multiple SAML libraries may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service
Please contact security@anaplan.com if you have any questions about this issue.
Tagged:
0
Categories
- All Categories
- 2.3K Anaplan Community
- Academy
- Anaplan Talent Builder
- Model Design Course
- The Anaplan Way
- Archive
- 2 Idea exchange
- 62 Enterprise Scale
- 1.1K Extensibility
- 21 Intelligence
- 1.6K Planning & Modeling
- 331 Security
- Community Connections
- Connections
- Experiences
- Groups
- Personas
- Employees
- CS Toolkit
- Customer Care Center
- Forums
- Academy & Training
- Community Feedback & Updates
- Japan
- Anaplan Community Japan
- Anaplan Community Japan Knowledge Base
- HyperCare Japan
- JP-Central
- Support-Japanese
- Partners
- Partner Leadership Council
- Partner Product Council
- 724 Platform
- Anapedia
- App Hub
- Centers Of Excellence
- Extensions
- Planual
- Platform Updates
- 724 User Experience
- Profile Builder
- Resources
- Anaplan Advocates
- Anaplan Live!
- Community
- Community Advancement
- Community Connections
- Partner Program
- The Official Master Anaplanner Program
- Videos
- Welcome to the Anaplan Community!
- Success Central
- Support
- Case Portal Link
- Common Support Questions
- HyperCare Redirect
- Known Issues and Workarounds
- Support test page
- SupportFAQ
- Survey
- 2 Training Day Takeaways