CVE Database
/

CVE-2015-5253

Back to search

CVE-2015-5253

Published: Nov 18, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."

VendorProductVersions

n/a

n/a

affected
n/a

References

1034162
vdb-entry
x_refsource_SECTRACK
RHSA-2016:0321
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now