5.5
CVSSv2

CVE-2015-5301

Published: 17/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.2 and 1.1.x prior to 1.1.1 does not properly check permissions, which allows remote authenticated users to cause a denial of service by deleting a SAML2 Service Provider (SP).

Vulnerable Product Search on Vulmon Subscribe to Product

ipsilon project ipsilon 0.4.0

ipsilon project ipsilon 0.5.0

ipsilon project ipsilon 0.6.0

ipsilon project ipsilon 1.1.0

ipsilon project ipsilon 1.0.0

ipsilon project ipsilon 1.0.1

ipsilon project ipsilon 0.1.0

ipsilon project ipsilon 0.3.0

Vendor Advisories

It was found that Ipsilon did not check whether a user is authorized to delete a service provider An authenticated user could use this flaw to delete any service provider, potentially resulting in a denial of service ...