CVE-2017-5697
published 2017-06-14CVE-2017-5697: Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.88%
55.4th percentile
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | active_management_technology_firmware | >= 10.0 < 10.0.50.1004 | 10.0.50.1004 |
| intel | active_management_technology_firmware | >= 11.0 < 11.0.0.1205 | 11.0.0.1205 |
| intel | active_management_technology_firmware | >= 11.6 < 11.6.25.1129 | 11.6.25.1129 |
| intel | active_management_technology_firmware | >= 9.1 < 9.1.40.1000 | 9.1.40.1000 |
| intel | active_management_technology_firmware | >= 9.5 < 9.5.60.1952 | 9.5.60.1952 |
| intel_corporation | active_mangement_technology | — | — |
| onelogin | ruby-saml | >= 0 < 1.11.0-1ubuntu0.1 | 1.11.0-1ubuntu0.1 |
| onelogin | ruby-saml | >= 0 < 1.13.0-1ubuntu0.1 | 1.13.0-1ubuntu0.1 |
| onelogin | ruby-saml | >= 0 < 1.15.0-1ubuntu0.24.04.1 | 1.15.0-1ubuntu0.24.04.1 |
| onelogin | ruby-saml | >= 0 < 1.1.2-1ubuntu1+esm1 | 1.1.2-1ubuntu1+esm1 |
| onelogin | ruby-saml | >= 0 < 1.7.2-1ubuntu0.1~esm1 | 1.7.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ruby SAML vulnerabilities
osv·2025-02-28·CVSS 7.5
CVE-2016-5697 Ruby SAML vulnerabilities
Ruby SAML vulnerabilities
It was discovered that Ruby SAML did not properly validate SAML responses.
An unauthenticated attacker could use this vulnerability to log in as an
abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5697)
It was discovered that Ruby SAML incorrectly utilized the results of XML
DOM traversal and canonicalization APIs. An unauthenticated attacker could
use this vulnerability to log in as an abitrary user. This issue only
affected Ubuntu 16.04 LTS. (CVE-2017-11428)
It was discovered that Ruby SAML did not properly verify the signature of
the SAML Response, allowing multiple elements with the same ID. An
unauthenticated attacker could use this vulnerability to log in as an
abitrary user. (CVE-2024-45409)
GHSA
GHSA-q5c9-crv8-jc57: Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9
ghsa_unreviewed·2022-05-17
CVE-2017-5697 [MEDIUM] CWE-1021 GHSA-q5c9-crv8-jc57: Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-14
Published