VYPR

Shibboleth Service Provider

by Shibboleth Consortium

CVEs (4)

  • CVE-2025-9943CriSep 10, 2025
    risk 0.59cvss 9.1epss 0.00

    An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL…

  • CVE-2023-36661HigJun 25, 2023
    risk 0.52cvss 7.5epss 0.03

    Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

  • CVE-2018-0489MedFeb 27, 2018
    risk 0.42cvss 6.5epss 0.02

    Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML…

  • CVE-2018-0486MedJan 13, 2018
    risk 0.42cvss 6.5epss 0.02

    Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a…