An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cortex_xsoar | Paloaltonetworks | 5.5.0 (including) | 5.5.0 (including) |
Cortex_xsoar | Paloaltonetworks | 5.5.0-70066 (including) | 5.5.0-70066 (including) |
Cortex_xsoar | Paloaltonetworks | 5.5.0-73387 (including) | 5.5.0-73387 (including) |
Cortex_xsoar | Paloaltonetworks | 5.5.0-75211 (including) | 5.5.0-75211 (including) |
Cortex_xsoar | Paloaltonetworks | 5.5.0-78518 (including) | 5.5.0-78518 (including) |
Cortex_xsoar | Paloaltonetworks | 5.5.0-94592 (including) | 5.5.0-94592 (including) |
Cortex_xsoar | Paloaltonetworks | 6.0.2 (including) | 6.0.2 (including) |
Cortex_xsoar | Paloaltonetworks | 6.0.2-90947 (including) | 6.0.2-90947 (including) |
Cortex_xsoar | Paloaltonetworks | 6.0.2-93351 (including) | 6.0.2-93351 (including) |
Cortex_xsoar | Paloaltonetworks | 6.0.2-94597 (including) | 6.0.2-94597 (including) |
Cortex_xsoar | Paloaltonetworks | 6.0.2-97682 (including) | 6.0.2-97682 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0 (including) | 6.1.0 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-1016923 (including) | 6.1.0-1016923 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-1031903 (including) | 6.1.0-1031903 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-1077664 (including) | 6.1.0-1077664 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-1209934 (including) | 6.1.0-1209934 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-1271079 (including) | 6.1.0-1271079 (including) |
Cortex_xsoar | Paloaltonetworks | 6.1.0-848144 (including) | 6.1.0-848144 (including) |
Cortex_xsoar | Paloaltonetworks | 6.2.0 (including) | 6.2.0 (including) |
Cortex_xsoar | Paloaltonetworks | 6.2.0-1271082 (including) | 6.2.0-1271082 (including) |
Cortex_xsoar | Paloaltonetworks | 6.2.0-1321594 (including) | 6.2.0-1321594 (including) |
Cortex_xsoar | Paloaltonetworks | 6.2.0-1473927 (including) | 6.2.0-1473927 (including) |