Back to search
CVE-2015-5372
Published: Sep 28, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150923 CVE-2015-5372 SAML SP Authentication Bypass in nevisAuth
mailing-list
x_refsource_FULLDISC
20150921 CVE-2015-5372 SAML SP Authentication Bypass in nevisAuth
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now