Skip to content

Test 10) Weak WS SecurityPolicy: Insufficient Supporting Token Protection

Yalçın YOLALAN edited this page Mar 28, 2018 · 2 revisions

Weak WS-SecurityPolicy: Insufficient Supporting Token Protection Test

Vulnerability Type Static

Test Web Service URI http://[yourhostName]/InsufficientSupportingTokenProtection.wsdl

Vulnerable Code Block The following WS-SecurityPolicy entry allows UsernameTokens to be sent in SOAP messages without a signature or encryption:

<sp:SupportingTokens xmlns:sp="">
    <wsp:Policy xmlns:wsp="">
        <sp:UsernameToken sp:IncludeToken="" />

Indications of Vulnerability Static analysis reveals that the wsdl file does not contain any SupportingToken XML tag.