5
CVSSv2

CVE-2015-5372

Published: 28/09/2015 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 prior to 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote malicious users to inject arbitrary SAML assertions via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

adnovum nevisauth

Github Repositories

SAML2 Burp Extension

SAML Raider - SAML2 Burp Extension Description SAML Raider is a Burp Suite extension for testing SAML infrastructures It contains two core functionalities: Manipulating SAML Messages and manage X509 certificates This software was created by Roland Bischofberger and Emanuel Duss (@emanuelduss) during a bachelor thesis at the Hochschule für Technik Rapperswil (HSR) Our p