An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.
The vulnerability results from improper implementation of the authentication mechanism (CWE-303, CWE-306) in the REST and SOAP API components of Tripwire Enterprise. When the 'Auto-synchronize LDAP Users, Roles, and Groups' feature is enabled, user identity verification in the SAML/LDAP flow is performed incorrectly, allowing it to be bypassed. It is sufficient that the attacker knows a valid user account name — no other form of authentication is required.
A remote unauthenticated attacker can gain privileged access to Tripwire Enterprise API interfaces, which may lead to unauthorized reading or modification of configuration data and monitoring managed by the system.
Apply patches available from the vendor according to the references (Fortra security advisory FI-2024-006: https://www.fortra.com/security/advisory/fi-2024-006). Until the fix is implemented, consider disabling the 'Auto-synchronize LDAP Users, Roles, and Groups' feature or restricting network access to REST and SOAP API interfaces only to trusted hosts.
Tripwire Enterprise (TE) version 9.1.0, configured with LDAP/Active Directory SAML authentication and the 'Auto-synchronize LDAP Users, Roles, and Groups' option enabled
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Red