Previous Topic: Data in the NoAccessURL Is Not Being Encoded (82810)

Next Topic: User Not Being Redirected to the Correct NoAccessURL (78834)

SMCONSUMERURL Query Parameter Subject to Malicious Modification (76739)

Symptom:

For SAML 1.x artifact binding, the SMCONSUMERURL query parameter of SAML1.x authentication URL can be exploited and the user can be redirected to a malicious site.

Solution:

To prevent any malicious modification of URLs, specify a value for the Consumer URL setting for the affiliate object. This value is set using the Policy Server User Interface. The Consumer URL takes precedence over SMCONSUMERURL query parameter.