CVE-2015-5253

Severity
4.0MEDIUM
EPSS
0.3%
top 43.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMay 13

Description

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

NVDapache/cxf3.0.03.0.7+2

🔴Vulnerability Details

3
GHSA
Improper Access Control in Apache CXF2022-05-13
OSV
Improper Access Control in Apache CXF2022-05-13
CVEList
CVE-2015-5253: The SAML Web SSO module in Apache CXF before 22015-11-18

📋Vendor Advisories

1
Red Hat
apache-cxf: SAML SSO processing is vulnerable to wrapping attack2015-11-14

💬Community

1
Bugzilla
CVE-2015-5253 apache-cxf: SAML SSO processing is vulnerable to wrapping attack2015-11-16
CVE-2015-5253 (MEDIUM CVSS 4) | The SAML Web SSO module in Apache C | cvebase.io