9.1
CVSSv3

CVE-2016-9814

Published: 17/02/2017 Updated: 04/03/2018
CVSS v2 Base Score: 8.5 | Impact Score: 7.8 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C

Vulnerability Summary

The validateSignature method in the SAML2\Utils class in SimpleSAMLphp prior to 1.14.10 and simplesamlphp/saml2 library prior to 1.9.1, 1.10.x prior to 1.10.3, and 2.x prior to 2.3.3 allows remote malicious users to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

Vulnerable Product Search on Vulmon Subscribe to Product

simplesamlphp simplesamlphp 1.10

simplesamlphp simplesamlphp

simplesamlphp saml2 2.0.0

simplesamlphp saml2 2.0.1

simplesamlphp saml2 1.10.1

simplesamlphp saml2 1.10.2

simplesamlphp saml2 2.3.2

simplesamlphp saml2 1.10

simplesamlphp saml2 2.3

simplesamlphp saml2 2.3.1

simplesamlphp saml2 2.1

simplesamlphp saml2 2.2

simplesamlphp saml2