4.3
CVSSv2

CVE-2015-1796

Published: 08/07/2015 Updated: 30/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The PKIX trust engines in Shibboleth Identity Provider prior to 2.4.4 and OpenSAML Java (OpenSAML-J) prior to 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote malicious users to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shibboleth identity provider

shibboleth opensaml java

Vendor Advisories

Debian Bug report logs - #780383 libopensaml2-java: CVE-2015-1796 Package: src:libopensaml2-java; Maintainer for src:libopensaml2-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 13 Mar 2015 07:30:01 UTC Severity: grave Ta ...