Unrated severityNVD Advisory· Published Sep 28, 2015· Updated May 6, 2026
CVE-2015-5372
CVE-2015-5372
Description
The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- blog.csnc.ch/2015/09/saml-sp-authentication-bypass-vulnerability-in-nevisauthnvd
- packetstormsecurity.com/files/133628/nevisAuth-Authentication-Bypass.htmlnvd
- seclists.org/fulldisclosure/2015/Sep/87nvd
- www.csnc.ch/misc/files/advisories/CVE-2015-5372_AdNovum_nevisAuth_Authentication_Bypass.txtnvd
- www.securityfocus.com/archive/1/536508/100/0/threadednvd
News mentions
0No linked articles in our index yet.