SAML Response Spoofing Vulnerability in SimpleSAMLphp
CVE-2016-9814

9.1CRITICAL

Key Information:

Vendor
CVE Published:
17 February 2017

What is CVE-2016-9814?

The validateSignature method in the SAML2\Utils class of SimpleSAMLphp and its simplesamlphp/saml2 library is vulnerable due to improper handling of return values. This flaw allows remote attackers to spoof SAML responses, potentially leading to unauthorized access or manipulation of user credentials. Moreover, this vulnerability can be exploited to trigger denial of service conditions through increased memory consumption, harming the application's availability. Users are advised to upgrade to the latest versions to mitigate these risks.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.