Is Via G&L vulnerable to “Authorization Bypass”?
2 years ago
Originally Published: 2016-08-30
Article Number
000059115
Applies To
RSA Product Set: Identity Management & Governance
RSA Versions: 6.9.1
 
Article Summary
It has been revealed that the application has poor authorization implementation.
A user who knows the direct path to the resource or a URL to call particular function, can access it without having proper role grant. 
The fact that resources and URLs for particular functions are hidden from the user interface does not prevent from unauthorized access/execution Authorization Bypass allows for executing certain actions without having permissions to do so. For example an unauthorized user can be able to execute administrative functions like adding another administrator user.

 
Resolution
It is not considered a severe vulnerability.

The implementation summary is,
*Unauthorized access of change request Edit/Cancel. Allowed only for user having ChangeRequest.Edit entitlement.
*Unauthorized access of Add/Change/Remove Access via any constructed URL (external) will be allowed with the below condition only,
   *    If URL contains Request button ID then validate the button for the availability of the user
   *    Else, if URL contains OID, validate value for 'Self' or Logged-in user ID
   *    Else logged-in user should be 'supervisor' or 'admin' with 'User Manage' entitlements

The fix is in the below versions:
6.9.1, 6.9.1 P17, 7.0.0, 7.0.1 P01, Highland Park (7.0.2)

 
Disclaimer
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact RSA Software Technical Support at 1- 800 995 5095. RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, EMC Corporation, distributes RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided 'as is' without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall RSA, its affiliates or suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.