4
CVSSv2

CVE-2015-5217

Published: 17/11/2015 Updated: 18/11/2015
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a duplicate SP name.

Vulnerable Product Search on Vulmon Subscribe to Product

ipsilon project ipsilon 0.3.0

ipsilon project ipsilon 0.1.0

ipsilon project ipsilon 0.4.0

ipsilon project ipsilon 0.5.0

ipsilon project ipsilon 0.6.0

ipsilon project ipsilon 1.0.0

Vendor Advisories

A flaw was discovered that the Ipsilon IdP server did not properly authorize a change of the provider's name Non-administrative users could use this flaw to change the name to a duplicate value, which could possibly lead to denial-of-service attack ...