VYPR

rpm package

opensuse/shibboleth-sp&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/shibboleth-sp&distro=openSUSE%20Leap%2016.0

Vulnerabilities (1)

  • CVE-2025-9943CriSep 10, 2025
    affected < 3.5.0-160000.3.1fixed 3.5.0-160000.3.1

    An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL in