CVE-2021-22506
Micro Focus Access Manager Information Leakage Vulnerability
Description
CVE-2021-22506 is a high-severity information leakage vulnerability in Micro Focus Access Manager affecting all versions prior to 5.0 with a CVSS score of 7.5. The vulnerability arises from an advanced configuration issue related to SAML service provider redirection when the Assertion Consumer Service (ACS) URL is used. An unauthenticated remote attacker can exploit this flaw to obtain sensitive information from the Access Manager system without requiring any user interaction. The vulnerability specifically impacts the confidentiality of the system, allowing disclosure of authentication-related data that could be used to facilitate further attacks against the identity management infrastructure.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microfocus | access manager | < 5.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
Weakness Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-200 describes situations where a product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. In CVE-2021-22506, Micro Focus Access Manager's SAML implementation inadvertently leaks sensitive configuration and authentication data through improper handling of service provider redirections, allowing unauthorized actors to access information that should remain confidential.
Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Impact Analysis
The impact of CVE-2021-22506 is rated High with a CVSS score of 7.5 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is remotely exploitable over the network with low attack complexity and requires no authentication or user interaction. The primary impact is on confidentiality, rated High, while integrity and availability are not affected. As an identity and access management system, Micro Focus Access Manager handles sensitive authentication data including SAML assertions, session tokens, and user identity information. Information leaked through this vulnerability could enable attackers to impersonate users, hijack sessions, or gain unauthorized access to protected applications that rely on Access Manager for authentication.
Exploit Maturity
CVE-2021-22506 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, added on November 3, 2021, confirming active exploitation in the wild. The EPSS score of 0.105 (93.2nd percentile) indicates a high exploitation probability. While specific public exploit code may not be widely circulated, the presence in the KEV catalog confirms that threat actors have successfully exploited this vulnerability in real-world attacks targeting identity management infrastructure.
Remediation
- Upgrade Micro Focus Access Manager to version 5.0 or later immediately, as this version addresses the information leakage vulnerability in the SAML service provider redirection handling.
- Review SAML configuration to ensure that Assertion Consumer Service URLs are properly configured and that redirection policies restrict responses to authorized endpoints only.
- Audit access logs for the Access Manager system to identify any suspicious authentication patterns, unusual SAML assertion requests, or unexpected redirection activity that could indicate exploitation.
- Implement network-level access controls to restrict access to the Access Manager administration and SAML endpoints from untrusted networks.
- Rotate SAML certificates and secrets after applying the patch, as sensitive authentication material may have been exposed through the information leakage vulnerability.
- Enable comprehensive logging and monitoring for the Access Manager system to detect future attempts to exploit similar information disclosure vectors.
Technical Details
The vulnerability exists in Micro Focus Access Manager's SAML (Security Assertion Markup Language) implementation, specifically in how the system handles service provider redirections involving the Assertion Consumer Service URL. When processing SAML authentication flows, Access Manager improperly handles certain advanced configuration scenarios related to SP-initiated redirections. This improper handling causes the system to leak sensitive information that should not be exposed to unauthenticated requestors. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects that the vulnerability is network-accessible, requires no authentication, and primarily impacts confidentiality. The information leakage could include SAML metadata, configuration details, or authentication tokens that an attacker could leverage to forge SAML assertions or bypass authentication controls. As Access Manager serves as a centralized identity provider, any information leakage from this system has cascading implications for all applications and services that depend on it for authentication and authorization.
Frequently Asked Questions
Is CVE-2021-22506 being actively exploited?
Yes. CVE-2021-22506 is listed in CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The vulnerability targets identity management infrastructure, making it particularly valuable for attackers seeking to compromise authentication systems and gain unauthorized access to protected resources.
What products are affected by CVE-2021-22506?
All versions of Micro Focus Access Manager prior to version 5.0 are affected. The vulnerability is in the SAML service provider redirection handling related to the Assertion Consumer Service URL.
How do I fix CVE-2021-22506?
Upgrade Micro Focus Access Manager to version 5.0 or later. After upgrading, review and audit your SAML configuration, rotate any SAML certificates and secrets, and check access logs for signs of prior exploitation.
How severe is CVE-2021-22506?
With a CVSS score of 7.5 (High), CVE-2021-22506 poses a significant risk. Although it only impacts confidentiality, the nature of the leaked information from an identity management system can enable further attacks including session hijacking, user impersonation, and unauthorized access to any applications that rely on the compromised Access Manager for authentication.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.