7.5
CVSSv2

CVE-2017-12868

Published: 01/09/2017 Updated: 01/07/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and previous versions, when used with PHP prior to 5.6, allows malicious users to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

simplesamlphp simplesamlphp