605
VMScore

CVE-2016-10127

Published: 03/03/2017 Updated: 08/03/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PySAML2 allows remote malicious users to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pysaml2 project pysaml2 -

Vendor Advisories

Debian Bug report logs - #850716 python-pysaml2: CVE-2016-10149 Package: src:python-pysaml2; Maintainer for src:python-pysaml2 is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Mon, 9 Jan 2017 15:30:05 UTC Severity: serious Tags: patch, security, upstream F ...
Debian Bug report logs - #859135 CVE-2016-10127: XXE attack via crafted SAML XML request or response Package: python-pysaml2; Maintainer for python-pysaml2 is Debian OpenStack <team+openstack@trackerdebianorg>; Source for python-pysaml2 is src:python-pysaml2 (PTS, buildd, popcon) Reported by: Antoine Beaupre <anarcat@or ...
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response ...