VYPR
Critical severity9.8NVD Advisory· Published Sep 21, 2016· Updated May 6, 2026

CVE-2016-4464

CVE-2016-4464

Description

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.cxf.fediz:fediz-springMaven
>= 1.2.0, < 1.2.31.2.3
org.apache.cxf.fediz:fediz-springMaven
>= 1.3.0, < 1.3.11.3.1
org.apache.cxf.fediz:fediz-spring2Maven
>= 1.2.0, < 1.2.31.2.3
org.apache.cxf.fediz:fediz-spring2Maven
>= 1.3.0, < 1.3.11.3.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

20

News mentions

0

No linked articles in our index yet.