cbcvebase.
CVE-2015-5253
published 2015-11-18

CVE-2015-5253: The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via…

PriorityP430medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
5.70%
92.2th percentile
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."

Affected

3 ranges
VendorProductVersion rangeFixed in
apachecxf< 2.7.182.7.18
apachecxf>= 3.0.0 < 3.0.73.0.7
apachecxf>= 3.1.0 < 3.1.33.1.3

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.