9.8
CVSSv3

CVE-2016-4464

Published: 21/09/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The application plugins in Apache CXF Fediz 1.2.x prior to 1.2.3 and 1.3.x prior to 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote malicious users to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf fediz 1.2.2

apache cxf fediz 1.2.0

apache cxf fediz 1.2.1

apache cxf fediz 1.3.0